RaqibCTI
CVE

CVE-2022-27593

P1⬤ KNOWN RANSOMWARE USE
QNAP Photo Station Externally Controlled Reference Vulnerability
QNAP · Photo Station
Date added (CISA)
2022-09-08
Remediation due
2022-09-29
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

Source: NVD ↗ · CISA KEV Catalog ↗