Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27597


A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later


Published

2023-03-29T07:15:08.403

Last Modified

2024-11-21T06:56:00.510

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-125
    CWE-489
    CWE-1295
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap qvr - Yes
Operating System qnap qts < 5.0.1.2346 Yes
Operating System qnap quts_hero < h5.0.1.2348 Yes
Operating System qnap qutscloud - Yes
Operating System qnap qvp-41b_firmware - Yes
Hardware qnap qvp-41b - No
Operating System qnap qvp-63b_firmware - Yes
Hardware qnap qvp-63b - No
Operating System qnap qvp-85b_firmware - Yes
Hardware qnap qvp-85b - No
Operating System qnap qvp-21a_firmware - Yes
Hardware qnap qvp-21a - No
Operating System qnap qvp-41a_firmware - Yes
Hardware qnap qvp-41a - No
Operating System qnap qvp-63a_firmware - Yes
Hardware qnap qvp-63a - No
Operating System qnap qvp-85a_firmware - Yes
Hardware qnap qvp-85a - No

References