logo

NHS Digital hints at exploit sightings of Arcserve UDP vulnerabilities

ID: e284afbb-8828-5647-a865-61c868a5302a

STIX ID: report--e284afbb-8828-5647-a865-61c868a5302a

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-05-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The UK's NHS and other CERTs warn that three Arcserve UDP vulnerabilities — an authentication bypass (CVE-2024-0799, CVSS 9.8), a path traversal/file upload leading to SYSTEM privilege (CVE-2024-0800, CVSS 8.8), and a DoS (CVE-2024-0801) — had proof-of-concept exploit code published shortly after disclosure. Authorities urge immediate patching and increased monitoring because successful exploitation could enable data theft, ransomware, or sabotage of backups, though concrete proof of widespread exploitation is not detailed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.