Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27593


An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later


Published

2022-09-08T11:15:19.503

Last Modified

2025-02-12T20:57:32.540

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-610
  • Type: Primary
    CWE-610

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap photo_station < 5.2.14 Yes
Operating System qnap qts 4.2.6 No
Application qnap photo_station < 5.4.15 Yes
Operating System qnap qts 4.3.3 No
Application qnap photo_station < 5.7.18 Yes
Operating System qnap qts 4.3.6 No
Application qnap photo_station < 6.0.22 Yes
Operating System qnap qts ≤ 4.5.4.2012 No
Operating System qnap qts 5.0.0 No
Application qnap photo_station < 6.1.2 Yes
Operating System qnap qts 5.0.1 No

References