CISA Known Exploited Vulnerability

CVE-2022-27593 Ransomware

QNAP · Photo Station

QNAP Photo Station Externally Controlled Reference Vulnerability

Date added
BOD 22-01 due date
CWE CWE-610
Ransomware Known

CISA description

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

Required action

Apply updates per vendor instructions.