PT-2020-11234 · Qnap · Qnap Quts Hero+1

Jan Hoff

·

Published

2020-12-10

·

Updated

2021-06-21

·

CVE-2019-7198

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QNAP QTS versions prior to 4.5.1.1456 build 20201015 QNAP QTS versions prior to 4.4.3.1354 build 20200702 QNAP QuTS hero versions prior to h4.5.1.1472 build 20201031
Description This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application.
Recommendations For QNAP QTS versions prior to 4.5.1.1456 build 20201015, update to QTS 4.5.1.1456 build 20201015 or later. For QNAP QTS versions prior to 4.4.3.1354 build 20200702, update to QTS 4.4.3.1354 build 20200702 or later. For QNAP QuTS hero versions prior to h4.5.1.1472 build 20201031, update to QuTS hero h4.5.1.1472 build 20201031 or later.

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7198

Affected Products

Qnap Qts
Qnap Quts Hero