First published: Mon Dec 07 2020(Updated: )
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QuTS hero | <h4.5.1.1472 | |
QNAP QTS | <4.4.3.1354 | |
QNAP QTS | <4.5.1.1456 |
QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this command injection vulnerability is CVE-2019-7198.
The severity of CVE-2019-7198 is critical.
The affected versions of QTS and QuTS hero are QuTS hero up to h4.5.1.1472 and QTS up to 4.4.3.1354.
An attacker can exploit CVE-2019-7198 by executing arbitrary commands in a compromised application.
Yes, QNAP has already fixed CVE-2019-7198 in the following versions: QuTS hero h4.5.1.1472 build 20201031 and later, QTS 4.5.1.1456 build 20201015 and later, QTS 4.4.3.1354 build 20201015 and later.