KEVIntel
Vulnerability detail
Enriched intelligence for a single CVE
9.8
CVSS
Critical
Critical
CVE-2019-7193
PUBLISHEDThis improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP...
Exploited in the wild
Used in malware
Remote
Low complexity
No user interaction
- Vendor
- QNAP
- Product
- QNAP NAS devices
- Published
- Dec 05, 2019
- EPSS
- —
Description
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
cisa
malware
ransomware
CVSS scores
CVSS v3.1
9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Jun 08, 2022 |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Exploit Used in Malware
-
Added to KEVIntel