CRITICAL KEV Used in ransomware campaigns ⚠
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system
Published Dec 5, 2019 ·Due Jun 22, 2022
9.8
CRITICALCVSS 3.1
EPSS 14.37%
Description
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Affected products
- Vendor n/a Product QNAP NAS devices Defaultn/a
- Version QTS 4.4.0 - QTS 4.4.1: before build 20190918, QTS 4.3.6: before build 20190919StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | QNAP NAS devices | n/a |
|
OR
- 4.3.6.0895
- 4.3.6.0907
- 4.3.6.0923
- 4.3.6.0944
- 4.3.6.0959
- 4.3.6.0979
- 4.3.6.0993
- 4.3.6.1013
- 4.3.6.1033
- 4.4.1.0948
- 4.4.1.0949
- 4.4.1.0978
- 4.4.1.0998
- 4.4.1.0999
- 4.4.1.1031
- 4.4.1.1033
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7193 government-resourceUS Government Resource
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7193 | government-resourceUS Government Resource | |
| https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner qnap
Published Dec 5, 2019
Updated Oct 21, 2025
Reserved Jan 29, 2019
Link CVE-2019-7193
CISA Vulnrichment
Updated Feb 6, 2025