NVD disclosure day

Published threat advisories for December 5, 2019

CVE advisoryKnown Exploit

CVE-2019-7195

QNAP Photo Station File Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

QNAP Photo Station allows remote attackers to access or modify system files. This external control of file name or path vulnerability creates a risk of unauthorized data access or alteration, potentially disrupting business operations and compromising system security.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-7194

QNAP Photo Station Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in QNAP Photo Station permits remote attackers to access or modify system files, impacting data confidentiality and integrity. This presents a business risk due to potential unauthorized data access or system compromise. Organizations should update Photo Station to the latest version.

• CISA KEV