CVE-2022-27593
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
87.9%
99.8th percentile
CISA KEV
Listed
Added 2022-09-08 · patch by 2022-09-29
Weakness / dates
—
Published — · modified —
Description
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.