CVE-2022-27599 is a sensitive information disclosure vulnerability affecting QNAP QVR Pro Client versions prior to 2.3.0.0420 on Windows and Mac operating systems. It allows local, authenticated administrators to access sensitive data via log files, potentially providing an easier path to information acquisition. Rated Medium severity with a CVSS score of 4.4, exploitation requires high privileges and local access, but has a high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0.0420CPE matchmatch criteria | cpe:2.3:a:qnap:qvr_pro_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.