PT-2022-7021 · Qnap · Qvr Pro Client
Runzi Zhao
·
Published
2022-03-21
·
Updated
2023-09-13
·
CVE-2022-27599
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QVR Pro Client versions prior to 2.3.0.0420
Description
The issue is related to insufficient protection of registration data in QVR Pro Client, which may allow an attacker to gain unauthorized access to protected information. An insertion of sensitive information into the log file vulnerability has been reported, potentially providing local authenticated administrators with an additional, less-protected path to acquiring the information via unspecified vectors.
Recommendations
For QVR Pro Client versions prior to 2.3.0.0420, update to version 2.3.0.0420 or later to resolve the issue. As a temporary workaround, consider restricting access to the log file to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qvr Pro Client