CVE-2022-27596
Published: Jan 30, 2023
Modified: Mar 27, 2025
CVSS v3.1
9.8
Description
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
| Vendor | Product | Versions |
|---|---|---|
QNAP Systems Inc. | QuTS hero | affected h5.0.1 - < h5.0.1.2248 build 20221215 |
QNAP Systems Inc. | QTS | affected 5.0.1 - < 5.0.1.2234 build 20221201 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now