CVE-2019-7201: High severity qnap netbak replicator vulnerability
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this issue in QNAP NetBak Replicator 4.5.12.1108.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7201?
CVE-2019-7201 is classified as a medium severity vulnerability due to its potential to allow local users to execute arbitrary code with elevated privileges.
How do I fix CVE-2019-7201?
To fix CVE-2019-7201, update to the latest version of QNAP NetBak Replicator that resolves the unquoted service path issue.
Who is affected by CVE-2019-7201?
CVE-2019-7201 affects users of QNAP NetBak Replicator versions up to and including 4.5.11.816.
What impact does CVE-2019-7201 have on systems?
CVE-2019-7201 allows unauthorized local users to execute arbitrary code, which can compromise system integrity and security.
Is CVE-2019-7201 exploitable from a remote location?
No, CVE-2019-7201 requires local access to exploit the vulnerability.