#VU66993 Input validation error in Photo Station - CVE-2022-27593

 

#VU66993 Input validation error in Photo Station - CVE-2022-27593

Published: September 6, 2022 / Updated: October 21, 2022


Vulnerability identifier: #VU66993
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2022-27593
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Photo Station
Software vendor:
QNAP Systems, Inc.

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to unspecified vulnerability. A remote non-authenticated attacker can send a specially crafted request to the affected system and execute arbitrary code.

Note, the vulnerability is being actively exploited in the wild by the DeadBolt ransomware.


Remediation

Install updates from vendor's website.

External links