PT-2020-8658 · Qnap Systems · Music Station

Published

2020-11-02

·

Updated

2022-11-16

·

CVE-2018-19950

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: QNAP Systems Inc. Music Station versions prior to 5.1.13 QNAP Systems Inc. Music Station versions prior to 5.2.9 QNAP Systems Inc. Music Station versions prior to 5.3.11
Description: This issue is a command injection vulnerability that could allow remote attackers to execute arbitrary commands if exploited.
Recommendations: For versions prior to 5.1.13, update to version 5.1.13 or later. For versions prior to 5.2.9, update to version 5.2.9 or later. For versions prior to 5.3.11, update to version 5.3.11 or later.

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2018-19950

Affected Products

Music Station