First published: Thu Dec 05 2019(Updated: )
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <6.0.3 | |
QNAP QTS | =4.4.1 | |
QNAP Photo Station | <5.7.10 | |
QNAP QTS | >=4.3.4<=4.4.0 | |
QNAP Photo Station | <5.4.9 | |
QNAP QTS | >=4.3.0<=4.3.3 | |
QNAP Photo Station | <5.2.11 | |
QNAP QTS | =4.2.6 | |
QNAP Photo Station | ||
All of | ||
QNAP Photo Station | <6.0.3 | |
QNAP QTS | =4.4.1 | |
All of | ||
QNAP Photo Station | <5.7.10 | |
QNAP QTS | >=4.3.4<=4.4.0 | |
All of | ||
QNAP Photo Station | <5.4.9 | |
QNAP QTS | >=4.3.0<=4.3.3 | |
All of | ||
QNAP Photo Station | <5.2.11 | |
QNAP QTS | =4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7195 is the QNAP Photo Station Path Traversal Vulnerability, which allows remote attackers to access or modify system files.
To fix CVE-2019-7195, QNAP recommends updating Photo Station to their latest version.
The severity of CVE-2019-7195 is critical, with a CVSS score of 9.8.
QNAP Photo Station versions up to 6.0.3 are affected by CVE-2019-7195.
No, QNAP QTS versions 4.4.1 and above are not vulnerable to CVE-2019-7195.