First published: Thu Dec 19 2024(Updated: )
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later QVPN Windows 2.0.0.1310 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QVPN Device Client | <2.0.0.1310 |
We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later QVPN Windows 2.0.0.1310 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27595 is classified as a medium severity vulnerability affecting the QVPN Device Client.
To fix CVE-2022-27595, upgrade your QVPN Device Client to version 2.0.0.1310 or later.
CVE-2022-27595 affects users of the QVPN Device Client versions earlier than 2.0.0.1310.
CVE-2022-27595 is an insecure library loading vulnerability.
If exploited, CVE-2022-27595 could allow local attackers with user access to execute unauthorized code or commands.