← Back

CVE-2019-7193

nvd nist
Published: Dec 5, 2019Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Affected (16)

Products: Qnap: Qts
1 product
Qts
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.6.0895
Version 4.3.6.0907
Version 4.3.6.0923
Version 4.3.6.0944
Version 4.3.6.0959
Version 4.3.6.0979
Version 4.3.6.0993
Version 4.3.6.1013
Version 4.3.6.1033
Version 4.4.1.0948 beta
Version 4.4.1.0949 beta
Version 4.4.1.0978 beta_2
Version 4.4.1.0998 beta_3
Version 4.4.1.0999 beta_3
Version 4.4.1.1031 beta_4
Version 4.4.1.1033 beta_4

References (5)

Source: security@qnapsecurity.com.tw
ExploitThird Party AdvisoryVDB Entry
Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.