CVE-2022-27593 is a critical externally controlled reference vulnerability affecting QNAP NAS devices running Photo Station, specifically allowing attackers to modify system files. With a CVSS score of 9.1, it presents a severe risk due to its network-based attack vector, low complexity, and high impact on integrity and availability. This vulnerability is actively exploited, notably in ransomware campaigns, and has garnered significant community attention and media coverage, despite the absence of public Metasploit or ExploitDB modules. QNAP has released patches for various QTS versions, including Photo Station 6.1.2 and later for QTS 5.0.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.14CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 5.4.15CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 5.7.18CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 6.0.22CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 6.1.2CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.