First published: Thu Sep 08 2022(Updated: )
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <5.2.14 | |
QNAP QTS | =4.2.6 | |
QNAP Photo Station | <5.4.15 | |
QNAP QTS | =4.3.3 | |
QNAP Photo Station | <5.7.18 | |
QNAP QTS | =4.3.6 | |
QNAP Photo Station | <6.0.22 | |
QNAP QTS | >=4.5.1<=4.5.4.2012 | |
QNAP QTS | =5.0.0 | |
QNAP Photo Station | <6.1.2 | |
QNAP QTS | =5.0.1 | |
QNAP Photo Station | ||
All of | ||
QNAP QTS | =4.2.6 | |
QNAP Photo Station | <5.2.14 | |
All of | ||
QNAP QTS | =4.3.3 | |
QNAP Photo Station | <5.4.15 | |
All of | ||
QNAP QTS | =4.3.6 | |
QNAP Photo Station | <5.7.18 | |
All of | ||
Any of | ||
QNAP QTS | >=4.5.1<=4.5.4.2012 | |
QNAP QTS | =5.0.0 | |
QNAP Photo Station | <6.0.22 | |
All of | ||
QNAP QTS | =5.0.1 | |
QNAP Photo Station | <6.1.2 |
QNAP have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27593 is an externally controlled reference to a resource vulnerability that affects QNAP NAS running Photo Station.
If exploited, CVE-2022-27593 could allow an attacker to modify system files.
QNAP Photo Station versions up to and including 5.4.15 are affected by CVE-2022-27593.
QNAP QTS versions 4.2.6, 4.3.3, 4.3.6, 4.5.1 to 4.5.4.2012, and 5.0.0 are not vulnerable to CVE-2022-27593.
To fix CVE-2022-27593, update to QTS 5.0.1 with Photo Station 6.1.2 or later.