peter bassill · operator
$ cve CVE-2019-7192 JSON

CVE-2019-7192 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 88.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.1% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-863
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2019-12-05
Last modified2026-06-17

CISA KEV

NameQNAP Photo Station Improper Access Control Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productQNAP / Photo Station
Ransomware useknown

Affected (2)

VendorProduct
qnapphoto station
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD