CISA Known Exploited Vulnerability

CVE-2019-7195 Ransomware

QNAP · Photo Station

QNAP Photo Station Path Traversal Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Known

CISA description

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

Required action

Apply updates per vendor instructions.