NHS Digital hints at exploit sightings of Arcserve UDP vulnerabilities
ID: e284afbb-8828-5647-a865-61c868a5302a
STIX ID: report--e284afbb-8828-5647-a865-61c868a5302a
Feed Name: The Register (Security)
The UK's NHS and other CERTs warn that three Arcserve UDP vulnerabilities — an authentication bypass (CVE-2024-0799, CVSS 9.8), a path traversal/file upload leading to SYSTEM privilege (CVE-2024-0800, CVSS 8.8), and a DoS (CVE-2024-0801) — had proof-of-concept exploit code published shortly after disclosure. Authorities urge immediate patching and increased monitoring because successful exploitation could enable data theft, ransomware, or sabotage of backups, though concrete proof of widespread exploitation is not detailed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
