CVE-2022-27596: Vulnerability in QTS
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
Which devices are affected by CVE-2022-27596?
QNAP devices running QuTS hero and QTS versions between 5.0.1 and 5.0.1.2234, and QuTS hero versions between h5.0.1 and h5.0.1.2248 are affected.
What is the severity of CVE-2022-27596?
The severity of CVE-2022-27596 is critical with a CVSS score of 9.8.
How can CVE-2022-27596 be exploited?
CVE-2022-27596 can be exploited by remote attackers to inject malicious code.
Has CVE-2022-27596 been fixed?
Yes, CVE-2022-27596 has been fixed in QuTS hero h5.0.1.2248 build 20221215 and later, and in QTS.
Where can I find more information about CVE-2022-27596?
You can find more information about CVE-2022-27596 at https://www.qnap.com/en/security-advisory/qsa-23-01.