ZeroHour

CVE-2022-27593

KEV ransomwarelarge

QNAP Photo Station Externally Controlled Reference Flaw Exploited by DeadBolt Ransomware

CISA: QNAP Photo Station Externally Controlled Reference Vulnerability

CVSS 3.1
9.1 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2022-27593 is a critical (CVSS 9.1) externally controlled reference to a resource (CWE-610, an SSRF-style flaw) in the Photo Station photo-sharing application for QNAP NAS devices running QTS. Because the flaw is reachable over the network with no privileges or user interaction required, an unauthenticated attacker who can reach a Photo Station instance can force the application to reference attacker-controlled resources and modify system files. This is the vulnerability the DeadBolt ransomware operation exploited to compromise and encrypt thousands of internet-facing QNAP NAS devices in 2022. Any QNAP NAS running vulnerable Photo Station versions across QTS 4.2.x through 5.x is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08, ransomware use is known, and EPSS puts the 30-day exploitation probability at 87.9% (100th percentile), though no public PoC is known.

What to do: Upgrade Photo Station to the fixed version for your QTS branch: 6.1.2+ on QTS 5.0.1, 6.0.22+ on QTS 5.0.0/4.5.x, 5.7.18+ on QTS 4.3.6, 5.4.15+ on QTS 4.3.3, and 5.2.14+ on QTS 4.2.6. If patching is not immediately possible, disable Photo Station or remove it from internet exposure, since the flaw requires no authentication. Check devices for DeadBolt compromise (encrypted files and ransom notes) and apply updates per CISA's KEV required action and QNAP's instructions.

Affected
QNAP Photo Station (QTS 5.0.1)all versions prior to Photo Station 6.1.2; fixed in 6.1.2 and later
QNAP Photo Station (QTS 5.0.0/4.5.x)all versions prior to Photo Station 6.0.22; fixed in 6.0.22 and later
QNAP Photo Station (QTS 4.3.6)all versions prior to Photo Station 5.7.18; fixed in 5.7.18 and later
QNAP Photo Station (QTS 4.3.3)all versions prior to Photo Station 5.4.15; fixed in 5.4.15 and later
QNAP Photo Station (QTS 4.2.6)all versions prior to Photo Station 5.2.14; fixed in 5.2.14 and later
Estimated exposure
large≈ tens of thousands of internet-exposed QNAP NAS devices running Photo Station, with thousands confirmed encrypted by DeadBolt — QNAP is a top consumer/SMB NAS brand with hundreds of thousands of NAS web interfaces visible in public internet scans, and the DeadBolt campaign against this Photo Station flaw hit thousands of devices, implying an exposed-but-unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CISA Known Exploited Vulnerability
Affected
QNAP Photo Station
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
photo station
Weakness
CWE-610
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news