QNAP Photo Station Externally Controlled Reference Vulnerability
Summary
| CVE | CVE-2022-27593 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-08 11:15:00 UTC |
| Updated | 2022-09-13 14:41:00 UTC |
| Description | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later |
Risk And Classification
EPSS: 0.931190000 probability, percentile 0.997960000 (date 2026-04-22)
CISA KEV: Listed on 2022-09-08; due 2022-09-29; ransomware use Known
Problem Types: CWE-610
CISA Known Exploited Vulnerability
| Vendor | QNAP |
|---|---|
| Product | Photo Station |
| Name | QNAP Photo Station Externally Controlled Reference Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.qnap.com/en/security-advisory/qsa-22-24; https://nvd.nist.gov/vuln/detail/CVE-2022-27593 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Qnap | Photo Station | All | All | All | All |
| Operating System | Qnap | Qts | 4.2.6 | All | All | All |
| Operating System | Qnap | Qts | 4.3.3 | All | All | All |
| Operating System | Qnap | Qts | 4.3.6 | All | All | All |
| Operating System | Qnap | Qts | 5.0.0 | All | All | All |
| Operating System | Qnap | Qts | 5.0.1 | All | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DeadBolt Ransomware - Security Advisory | QNAP | CONFIRM | www.qnap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.