CVE-2019-7192

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*

History

06 Feb 2025, 21:15

Type Values Removed Values Added
References (CONFIRM) https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 - Vendor Advisory () https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 - Vendor Advisory
References (MISC) http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2019-12-05 17:15

Updated : 2025-02-13 14:18


NVD link : CVE-2019-7192

Mitre link : CVE-2019-7192


JSON object : View

Products Affected

qnap

  • photo_station
  • qts
CWE
CWE-863

Incorrect Authorization