CVE-2022-27593
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/09/2022
Last modified:
12/02/2025
Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | 5.2.14 (excluding) | |
cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | 5.4.15 (excluding) | |
cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | 5.7.18 (excluding) | |
cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | 6.0.22 (excluding) | |
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | 4.5.1 (including) | 4.5.4.2012 (including) |
cpe:2.3:o:qnap:qts:5.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | 6.1.2 (excluding) | |
cpe:2.3:o:qnap:qts:5.0.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page