---
cve: "CVE-2022-27593"
severity: "CRITICAL"
cvss: 10.0
epss: "87.9%"
vendor: "QNAP Systems Inc."
kev: true
exploited: true
published: "2022-09-08 11:15:19"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T12:18:42+02:00"
---

# CVE-2022-27593

> 10.0 CRITICAL · ⚠️ CISA KEV (1464 Tage) · 🔓 Exploited

## Beschreibung

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.qnap.com/en/security-advisory/qsa-22-24>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27593>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-27593) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
