CVE-2022-27593
CVE Published | 2022-09-08 |
---|---|
Related CWE(s) | CWE-610: Externally Controlled Reference to a Resource in Another Sphere |
Related Vendor(s) | qnap |
Related Product(s) | photo_station |
Exploitation Reported (CISA KEV) | 2022-09-08 |
CVSS 3 Base Score | 10.0 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph