CVE-2022-27596

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
30/01/2023
Last modified:
07/11/2023

Description

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code.<br /> We have already fixed this vulnerability in the following versions of QuTS hero, QTS:<br /> QuTS hero h5.0.1.2248 build 20221215 and later<br /> QTS 5.0.1.2234 build 20221201 and later<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* 5.0.1 (including) 5.0.1.2234 (excluding)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:* h5.0.1 (including) h5.0.1.2248 (excluding)


References to Advisories, Solutions, and Tools