Published:2022/05/11  Last Updated:2022/05/11

JVNVU#95992089
Command injection vulnerability in QNAP VioStar series NVR

Overview

VioStar series NVR provided by QNAP Systems contains a command injection vulnerability.

Products Affected

  • QNAP VioStar series NVR

Description

VioStar series NVR provided by QNAP Systems, Inc. contains a command injection vulnerability (CVE-2022-27588, CWE-77).

Impact

An arbitrary command may be executed by a remote attacker.

Solution

Update the firmware
Apply the appropriate firmware update according to the information provided by the developer.
The developer has released fixed version below.

  • QVR 5.1.6 build 20220401

Vendor Status

Vendor Link
QNAP Systems, Inc. QSA-22-07: Vulnerability in QVR

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score: 9.8
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)

Credit

Chuya Hayakawa of 00One, Inc. reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia