CVE-2022-27593
KEV ransomwarelargeQNAP Photo Station Externally Controlled Reference Flaw Exploited by DeadBolt Ransomware
CISA: QNAP Photo Station Externally Controlled Reference Vulnerability
CVE-2022-27593 is a critical (CVSS 9.1) externally controlled reference to a resource (CWE-610, an SSRF-style flaw) in the Photo Station photo-sharing application for QNAP NAS devices running QTS. Because the flaw is reachable over the network with no privileges or user interaction required, an unauthenticated attacker who can reach a Photo Station instance can force the application to reference attacker-controlled resources and modify system files. This is the vulnerability the DeadBolt ransomware operation exploited to compromise and encrypt thousands of internet-facing QNAP NAS devices in 2022. Any QNAP NAS running vulnerable Photo Station versions across QTS 4.2.x through 5.x is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08, ransomware use is known, and EPSS puts the 30-day exploitation probability at 87.9% (100th percentile), though no public PoC is known.
What to do: Upgrade Photo Station to the fixed version for your QTS branch: 6.1.2+ on QTS 5.0.1, 6.0.22+ on QTS 5.0.0/4.5.x, 5.7.18+ on QTS 4.3.6, 5.4.15+ on QTS 4.3.3, and 5.2.14+ on QTS 4.2.6. If patching is not immediately possible, disable Photo Station or remove it from internet exposure, since the flaw requires no authentication. Check devices for DeadBolt compromise (encrypted files and ransom notes) and apply updates per CISA's KEV required action and QNAP's instructions.
| QNAP Photo Station (QTS 5.0.1) | all versions prior to Photo Station 6.1.2; fixed in 6.1.2 and later |
| QNAP Photo Station (QTS 5.0.0/4.5.x) | all versions prior to Photo Station 6.0.22; fixed in 6.0.22 and later |
| QNAP Photo Station (QTS 4.3.6) | all versions prior to Photo Station 5.7.18; fixed in 5.7.18 and later |
| QNAP Photo Station (QTS 4.3.3) | all versions prior to Photo Station 5.4.15; fixed in 5.4.15 and later |
| QNAP Photo Station (QTS 4.2.6) | all versions prior to Photo Station 5.2.14; fixed in 5.2.14 and later |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
- Affected
- QNAP Photo Station
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- photo station
- Weakness
- CWE-610
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H