Skip to content
COOEY

EXPOSURES › CVE-2019-7192

CVE-2019-7192

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-7192 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatchedauth-bypass

QNAP Photo Station's improper access control flaw allowed remote attackers to bypass authentication and gain unauthorized system access.

QNAP Photo Station suffered an improper access control vulnerability that let remote attackers bypass authentication and gain unauthorized access to the system. This failure is critical for DIB organizations because it directly enables data exfiltration and ransomware deployment, violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure Photo Station is patched or replaced, and verify that all QNAP NAS devices running third-party apps are assessed for similar flaws.

Shame score — A critical access control flaw in a widely deployed NAS product was actively exploited in the wild to deploy ransomware, demonstrating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.