7.5

CVE-2022-27600

QTS, QuTS hero, QuTScloud

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2277 and later
QTS 4.5.4.2280 build 20230112 and later
QuTS hero h5.0.1.2277 build 20230112 and later
QuTS hero h4.5.4.2374 build 20230417 and later
QuTScloud c5.0.1.2374 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version >= 4.5.1 < 4.5.4.2280
Qnap ≫ Qts Version >= 5.0.0 < 5.0.1.2277
Qnap ≫ Qts Version 4.5.4.2280 Update -
Qnap ≫ Qts Version 5.0.1.2277 Update -
Qnap ≫ Quts Hero Version >= h4.5.1 < h4.5.4.2374
Qnap ≫ Quts Hero Version >= h5.0 < h5.0.1.2277
Qnap ≫ Quts Hero Version h4.5.4.2374 Update -
Qnap ≫ Quts Hero Version h5.0.1.2277 Update -
Qnap ≫ Qutscloud Version >= c5.0.1 < c5.0.1.2374
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@qnapsecurity.com.tw 6.8 2.2 4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.qnap.com/en/security-advisory/qsa-23-09
Vendor Advisory