CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2022-27593

CVSS 10.0v3.1pub. 2022-09-08upd. 2025-11-03

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
  • Qnap Photo Station

    APP
    Qnap
    < 6.0.22< 5.4.15< 6.1.2< 5.7.18< 5.2.14
  • Qnap Qts

    OS
    Qnap
    4.2.64.3.34.3.65.0.05.0.14.5.1 – 4.5.4.2012

CISA KEV — detailsi

Vendori
QNAP
Producti
Photo Station
Added to KEVi
September 8, 2022
Remediation deadline (US Federal)i
September 29, 2022(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 29 września 2022
CWE
References

Related vulnerabilities

CVE-2021-28799CRITICAL10.0⚠ KEVPL ✓same product

QNAP HBS 3 — nieautoryzowane logowanie zdalne do urządzenia NAS

CVE-2020-2509CRITICAL9.8⚠ KEVPL ✓same product

Command injection w QNAP QTS i QuTS hero — zdalne wykonanie kodu

CVE-2018-19949CRITICAL9.8⚠ KEVPL ✓same product

Command injection w QNAP QTS umożliwiający zdalne wykonanie kodu

CVE-2019-7193CRITICAL9.8⚠ KEVPL ✓same product

QNAP QTS — zdalne wstrzykiwanie kodu przez błąd walidacji danych wejściowych

CVE-2019-7192CRITICAL9.8⚠ KEVPL ✓same product

QNAP Photo Station — nieautoryzowany dostęp zdalny (RCE)