CVE-2019-7195
Summary
| CVE | CVE-2019-7195 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-05 17:15:00 UTC |
| Updated | 2022-04-22 19:59:00 UTC |
| Description | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
Risk And Classification
EPSS: 0.941100000 probability, percentile 0.999080000 (date 2026-04-01)
CISA KEV: Listed on 2022-06-08; due 2022-06-22; ransomware use Known
Problem Types: CWE-22
CISA Known Exploited Vulnerability
| Vendor | QNAP |
|---|---|
| Product | Photo Station |
| Name | QNAP Photo Station Path Traversal Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-7195 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Qnap | Photo Station | All | All | All | All |
| Application | Qnap | Photo Station | All | All | All | All |
| Operating System | Qnap | Qts | 4.2.6 | All | All | All |
| Operating System | Qnap | Qts | 4.4.1 | All | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
| Operating System | Qnap | Qts | 4.2.6 | All | All | All |
| Operating System | Qnap | Qts | 4.4.1 | All | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Vulnerabilities in QTS and Photo Station - Technical Advisory | QNAP | CONFIRM | www.qnap.com | Vendor Advisory |
| QNAP QTS And Photo Station 6.0.3 Remote Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.