Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-27593
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DeadBolt Ransomware
Source: NVD (National Vulnerability Database)
Vulnerability Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
资源在另一范围的外部可控制索引
Source: NVD (National Vulnerability Database)
Vulnerability Title
QNAP Systems Photo Station 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
QNAP Systems Photo Station是中国威联通科技(QNAP Systems)公司的一个线上相册。用于整理 Qnap Nas 上的多媒体内容(相片和影片)。 QNAP Systems Photo Station 存在安全漏洞,攻击者利用该漏洞可以执行 DeadBolt 勒索软件活动,以下产品和版本受到影响:QTS 5.0.1:Photo Station 6.1.2 之前版本、QTS 5.0.0/4.5.x:Photo Station 6.0.22 之前版本、QTS 4.3.6:Photo
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
QNAP Systems Inc.Photo Station unspecified ~ 6.1.2 -
QNAP Systems Inc.Photo Station unspecified ~ 6.0.22 -
QNAP Systems Inc.Photo Station unspecified ~ 6.0.22 -
QNAP Systems Inc.Photo Station unspecified ~ 5.7.18 -
QNAP Systems Inc.Photo Station unspecified ~ 5.4.15 -
QNAP Systems Inc.Photo Station unspecified ~ 5.2.14 -
II. Public POCs for CVE-2022-27593
#POC DescriptionSource LinkShenlong Link
1QNAP QTS Photo Station External Reference is vulnerable to local file inclusion via an externally controlled reference to a resource vulnerability. If exploited, this could allow an attacker to modify system files. The vulnerability is fixed in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-27593.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-27593
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-27593

No comments yet


Leave a comment