EXPOSURES › CVE-2022-27593
CVE-2022-27593
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP Photo Station's externally controlled reference vulnerability allowed attackers to modify system files and was actively exploited in a Deadbolt ransomware campaign.
The vulnerability in QNAP Photo Station enabled remote modification of system files, directly facilitating ransomware deployment. DIB organizations must ensure all internet-facing NAS devices are patched and monitored for known KEV vulnerabilities to prevent similar compromises.
Shame score — A known, externally controlled reference vulnerability was actively exploited in the wild for ransomware, indicating severe negligence in patch management and threat intelligence integration.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.