Published:2022/05/11 Last Updated:2022/05/11
JVNVU#95992089
Command injection vulnerability in QNAP VioStar series NVR
Overview
VioStar series NVR provided by QNAP Systems contains a command injection vulnerability.
Products Affected
- QNAP VioStar series NVR
Description
VioStar series NVR provided by QNAP Systems, Inc. contains a command injection vulnerability (CVE-2022-27588, CWE-77).
Impact
An arbitrary command may be executed by a remote attacker.
Solution
Update the firmware
Apply the appropriate firmware update according to the information provided by the developer.
The developer has released fixed version below.
- QVR 5.1.6 build 20220401
Vendor Status
Vendor | Link |
QNAP Systems, Inc. | QSA-22-07: Vulnerability in QVR |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score:
9.8
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Credit
Chuya Hayakawa of 00One, Inc. reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.