EUVD-2022-32094
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 8 Sept 2022. Evidence sources: cisa_kev.
- ENISA score
- 10.0 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
