peter bassill · operator
$ cve CVE-2022-27593 JSON

CVE-2022-27593 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 87.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-29.

Description

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
EPSS87.91% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-610
On CISA KEVyes — remediate by 2022-09-29
Public exploitnone known
Published2022-09-08
Last modified2026-06-17

CISA KEV

NameQNAP Photo Station Externally Controlled Reference Vulnerability
Added2022-09-08
Due2022-09-29
Vendor / productQNAP / Photo Station
Ransomware useknown

Affected (2)

VendorProduct
qnapphoto station
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD