Back to overview

CVE-2022-27593

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

Metadata

CVE ID
CVE-2022-27593
State
PUBLISHED
Assigner
qnap
Reserved
2022-03-21 00:00 UTC
Published
2022-09-08 11:00 UTC
Last updated
2025-10-21 23:15 UTC
Primary CWE
CWE-610
CWE-610 Externally Controlled Reference to a Resource in Ano…
Vendor / Product
QNAP Systems Inc. / Photo Station
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
partial
CISA Known Exploited Vulnerability
Vulnerability name
QNAP Photo Station Externally Controlled Reference Vulnerability
Vendor
QNAP
Product
Photo Station
Added to KEV
2022-09-08
Due date
2022-09-29
Ransomware
Known use
Required action
Apply updates per vendor instructions.
CISA description
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.
Affected products (6)
VendorProductPlatformVersions
QNAP Systems Inc. Photo Station QTS 5.0.1 unspecified < 6.1.2
QNAP Systems Inc. Photo Station QTS 5.0.0 unspecified < 6.0.22
QNAP Systems Inc. Photo Station QTS 4.5.x unspecified < 6.0.22
QNAP Systems Inc. Photo Station QTS 4.3.6 unspecified < 5.7.18
QNAP Systems Inc. Photo Station QTS 4.3.3 unspecified < 5.4.15
QNAP Systems Inc. Photo Station QTS 4.2.6 unspecified < 5.2.14
Weakness (CWE)
CWESourceDescription
CWE-610 cna CWE-610 Externally Controlled Reference to a Resource in Another Sphere
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Back to overview