2.7
CWE
125 1295 489
Advisory Published
Updated

CVE-2022-27597

First published: Wed Mar 29 2023(Updated: )

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later

Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw

Affected SoftwareAffected VersionHow to fix
Qnap Qvr
QNAP QTS<5.0.1.2346
QNAP QuTS hero<h5.0.1.2348
QNAP QuTScloud
Qnap Qvp-41b Firmware
Qnap Qvp-41b
Qnap Qvp-63b Firmware
Qnap Qvp-63b
Qnap Qvp-85b Firmware
Qnap Qvp-85b
Qnap Qvp-21a Firmware
Qnap Qvp-21a
Qnap Qvp-41a Firmware
Qnap Qvp-41a
Qnap Qvp-63a Firmware
Qnap Qvp-63a
Qnap Qvp-85a Firmware
Qnap Qvp-85a

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-27597?

    CVE-2022-27597 is a vulnerability that affects QNAP operating systems and allows remote authenticated administrators to get secret values.

  • Which QNAP operating systems are affected by CVE-2022-27597?

    The following QNAP operating systems are affected by CVE-2022-27597: QTS, QuTS hero, QuTScloud, QVR Pro appliances.

  • What is the severity of CVE-2022-27597?

    CVE-2022-27597 has a severity rating of low (2.7).

  • How can remote authenticated administrators exploit CVE-2022-27597?

    Remote authenticated administrators can exploit CVE-2022-27597 to get secret values.

  • Is there a fix available for CVE-2022-27597?

    Please refer to the QNAP security advisory (QSA-23-06) for the fix for CVE-2022-27597.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203