peter bassill · operator
$ cve CVE-2019-7194 JSON

CVE-2019-7194 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 83.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS83.12% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-06-22
Public exploitnone known
Published2019-12-05
Last modified2026-06-17

CISA KEV

NameQNAP Photo Station Path Traversal Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productQNAP / Photo Station
Ransomware useknown

Affected (2)

VendorProduct
qnapphoto station
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD