Information disclosure in QNAP Systems, Inc. products - CVE-2022-27598
Published: March 30, 2023
Vulnerability identifier: #VU74195
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27598
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
QuTScloud
QVP (QVR Pro appliances)
QuTS hero
QNAP QTS
QVP (QVR Pro appliances)
QuTS hero
QNAP QTS
How to mitigate CVE-2022-27598
Install updates from vendor's website.
QuTS hero - update to h5.0.1.2348 build 20230324
QNAP QTS - update to 5.0.1.2346 20230322
QNAP QTS - update to 5.0.1.2346 20230322