CVE-2022-27593
Last modified
CVE-2022-27593 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. CISA has confirmed active exploitation in the wild. EPSS estimates a 87.91% chance of exploitation in the next 30 days.
Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Photo Station | < 5.2.14 |
| Qnap | Photo Station | < 5.4.15 |
| Qnap | Photo Station | < 5.7.18 |
| Qnap | Photo Station | < 6.0.22 |
| Qnap | Photo Station | < 6.1.2 |
References
- https://www.qnap.com/en/security-advisory/qsa-22-24Vendor Advisory
- https://www.qnap.com/en/security-advisory/qsa-22-24Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27593US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-27593?
How severe is CVE-2022-27593?
How do I fix CVE-2022-27593?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-27584Password recovery vulnerability in SICK SIM2000ST Partnumber…9.8
- CVE-2022-27585Password recovery vulnerability in SICK SIM1000 FX Partnumbe…9.8
- CVE-2022-27586Password recovery vulnerability in SICK SIM1004 Partnumber 1…9.8
- CVE-2022-27588We have already fixed this vulnerability in the following ve…9.8
- CVE-2022-2759Delta Electronics Delta Robot Automation Studio (DRAS) versi…8.6
- CVE-2022-27592An unquoted search path or element vulnerability has been re…6.7
- CVE-2022-27595An insecure library loading vulnerability has been reported …7.8
- CVE-2022-27596A vulnerability has been reported to affect QNAP device runn…9.8
- CVE-2022-27597A vulnerability has been reported to affect QNAP operating s…2.7
- CVE-2022-27598A vulnerability has been reported to affect QNAP operating s…2.7
- CVE-2022-27599An insertion of sensitive information into Log file vulnerab…4.4
- CVE-2022-2760In affected versions of Octopus Deploy it is possible to rev…4.3
Are you affected by CVE-2022-27593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
