CVE-2019-7194
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- QNAP Photo Station Path Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 83% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-22
מוצרים מושפעים
qnap: photo station; qnap: qts
קישורים
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-R… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-R… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource