peter bassill · operator
$ cve CVE-2019-7193 JSON

CVE-2019-7193 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 14.4% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.37% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2019-12-05
Last modified2026-06-17

CISA KEV

NameQNAP QTS Improper Input Validation Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productQNAP / QTS
Ransomware useknown

Affected (1)

VendorProduct
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD