CVE-2022-27595

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later QVPN Windows 2.0.0.1310 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qvpn:*:*:*:*:*:windows:*:*

History

08 Dec 2025, 18:48

Type Values Removed Values Added
Summary
  • (es) Se ha informado de una vulnerabilidad de carga de librerías inseguras que afecta a QVPN Device Client. Si se explota, la vulnerabilidad podría permitir que atacantes locales que hayan obtenido acceso de usuario ejecuten código o comandos no autorizados. Ya hemos corregido la vulnerabilidad en las siguientes versiones: QVPN Windows 2.0.0.1316 y posteriores QVPN Windows 2.0.0.1310 y posteriores
First Time Qnap qvpn
Qnap
CPE cpe:2.3:a:qnap:qvpn:*:*:*:*:*:windows:*:*
References () https://www.qnap.com/en/security-advisory/qsa-23-04 - () https://www.qnap.com/en/security-advisory/qsa-23-04 - Vendor Advisory

19 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 02:15

Updated : 2025-12-08 18:48


NVD link : CVE-2022-27595

Mitre link : CVE-2022-27595

CVE.ORG link : CVE-2022-27595


JSON object : View

Products Affected

qnap

  • qvpn
CWE
CWE-427

Uncontrolled Search Path Element