CVE-2019-7198
Last modified
CVE-2019-7198 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Quts Hero | < h4.5.1.1472 |
| Qnap | Qts | < 4.4.3.1354 |
| Qnap | Qts | < 4.5.1.1456 |
References
- https://www.qnap.com/en/security-advisory/qsa-20-16Vendor Advisory
- https://www.qnap.com/en/security-advisory/qsa-20-16Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7198?
How severe is CVE-2019-7198?
How do I fix CVE-2019-7198?
Are you affected by CVE-2019-7198?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
