CVE-2022-27600

Published: Dic 19, 2024 Last Modified: Dic 08, 2025 EU-VD ID: EUVD-2022-32101 Aliases: GSD-2022-27600
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,8
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2277 and later
QTS 4.5.4.2280 build 20230112 and later
QuTS hero h5.0.1.2277 build 20230112 and later
QuTS hero h4.5.4.2374 build 20230417 and later
QuTScloud c5.0.1.2374 and later

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0075
Percentile
0,7th
Updated

EPSS Score Trend (Last 90 Days)

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
All platforms may be affected
View CWE Details
798

Use of Hard-coded Credentials

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Other
Potential Impacts:
Bypass Protection Mechanism Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Other
Applicable Platforms
Technologies: ICS/OT, Mobile
View CWE Details
Operating System

Quts Hero by Qnap

cpe:2.3:o:qnap:quts_hero:h5.0.1.2277:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Quts Hero by Qnap

Version Range Affected
From h4.5.1 (inclusive)
To h4.5.4.2374 (exclusive)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Quts Hero by Qnap

cpe:2.3:o:qnap:quts_hero:h4.5.4.2374:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Qts by Qnap

Version Range Affected
From 5.0.0 (inclusive)
To 5.0.1.2277 (exclusive)
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Qts by Qnap

cpe:2.3:o:qnap:qts:5.0.1.2277:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Quts Hero by Qnap

Version Range Affected
From h5.0 (inclusive)
To h5.0.1.2277 (exclusive)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Qts by Qnap

cpe:2.3:o:qnap:qts:4.5.4.2280:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Qts by Qnap

Version Range Affected
From 4.5.1 (inclusive)
To 4.5.4.2280 (exclusive)
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Qutscloud by Qnap

Version Range Affected
From c5.0.1 (inclusive)
To c5.0.1.2374 (exclusive)
cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.qnap.com/en/security-advisory/qsa-23-09