Junglewise Threat Intelligence

CVE-2019-7193: QNAP QTS Improper Input Validation Vulnerability

CVE-2019-7193 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-08

Technologies: QNAP QTS. Vendors: QNAP, QNAP Systems.

Executive brief

QNAP QTS contains an improper input validation vulnerability that allows remote attackers to inject arbitrary code into the system. The vulnerability has been observed being exploited in the wild and affects multiple versions of the QTS operating system.

Affected products

  • QNAP Systems QTS 4.3.6.0895 through 4.3.6.1033, 4.4.1.0948 through 4.4.1.1033 (beta)

Timeline

  • 2019-11-25: advisory: Vendor advisory published by QNAP (NAS-201911-25)
  • 2019-12-10: disclosed: Initial NVD analysis and CVSS scoring
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: other: Vulnerability published to NVD

Related threats