CVE-2022-27593 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 87.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-09-29.
Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H |
| EPSS | 87.91% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-610 |
| On CISA KEV | yes — remediate by 2022-09-29 |
| Public exploit | none known |
| Published | 2022-09-08 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | QNAP Photo Station Externally Controlled Reference Vulnerability |
|---|---|
| Added | 2022-09-08 |
| Due | 2022-09-29 |
| Vendor / product | QNAP / Photo Station |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| qnap | photo station |
| qnap | qts |
References
→ the Explorer · watch your stack · NVD