CVE-2022-27592

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
06/09/2024
Last modified:
24/09/2024

Description

An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Windows 10 SP1, Windows 11, Mac OS, and Mac M1: QVR Smart Client 2.4.0.0570 and later

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:qvr_smart_client:*:*:*:*:*:*:*:* 2.4.0 (including) 2.4.0.0570 (excluding)


References to Advisories, Solutions, and Tools