← Back

CVE-2019-7198

nvd nist
Published: Dec 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later

Affected (3)

Products: Qnap: Quts Hero, Qts
2 products
Quts Hero
Qts
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before h4.5.1.1472
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.4.3.1354
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.5.1.1456

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.