PT-2022-7021 · Qnap · Qvr Pro Client

Runzi Zhao

·

Published

2022-03-21

·

Updated

2023-09-13

·

CVE-2022-27599

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QVR Pro Client versions prior to 2.3.0.0420
Description The issue is related to insufficient protection of registration data in QVR Pro Client, which may allow an attacker to gain unauthorized access to protected information. An insertion of sensitive information into the log file vulnerability has been reported, potentially providing local authenticated administrators with an additional, less-protected path to acquiring the information via unspecified vectors.
Recommendations For QVR Pro Client versions prior to 2.3.0.0420, update to version 2.3.0.0420 or later to resolve the issue. As a temporary workaround, consider restricting access to the log file to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2023-06622
CVE-2022-27599

Affected Products

Qvr Pro Client