CVE Vulnerabilities

CVE-2019-7193

Published: Dec 05, 2019 | Modified: Oct 27, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Affected Software

NameVendorStart VersionEnd Version
QtsQnap4.3.6.0895 (including)4.3.6.0895 (including)
QtsQnap4.3.6.0907 (including)4.3.6.0907 (including)
QtsQnap4.3.6.0923 (including)4.3.6.0923 (including)
QtsQnap4.3.6.0944 (including)4.3.6.0944 (including)
QtsQnap4.3.6.0959 (including)4.3.6.0959 (including)
QtsQnap4.3.6.0979 (including)4.3.6.0979 (including)
QtsQnap4.3.6.0993 (including)4.3.6.0993 (including)
QtsQnap4.3.6.1013 (including)4.3.6.1013 (including)
QtsQnap4.3.6.1033 (including)4.3.6.1033 (including)
QtsQnap4.4.1.0948-beta (including)4.4.1.0948-beta (including)
QtsQnap4.4.1.0949-beta (including)4.4.1.0949-beta (including)
QtsQnap4.4.1.0978-beta_2 (including)4.4.1.0978-beta_2 (including)
QtsQnap4.4.1.0998-beta_3 (including)4.4.1.0998-beta_3 (including)
QtsQnap4.4.1.0999-beta_3 (including)4.4.1.0999-beta_3 (including)
QtsQnap4.4.1.1031-beta_4 (including)4.4.1.1031-beta_4 (including)
QtsQnap4.4.1.1033-beta_4 (including)4.4.1.1033-beta_4 (including)

References