HomeSecurityQNAP: Disable AFP until we fix some important bugs

QNAP: Disable AFP until we fix some important bugs

This week, Taiwanese company QNAP asked customers to disable the AFP file service protocol on their network-attached storage (NAS) devices until it fixes several critical Netatalk vulnerabilities.

See also: QNAP to customers: Disable UPnP Port Forwarding on routers

QNAP AFP

Netatalk is an open source implementation of AFP (short for Apple Filing Protocol) that allows *NIX/*BSD systems to act as an AppleShare (AFP) file server for macOS clients.

On QNAP NAS devices, AFP allows macOS to access data on the NAS. According to QNAP, it is still used because it “supports many unique macOS features that are not supported by other protocols.”

Members of the NCC Group's EDG team exploited one of these security flaws, tracked as CVE-2022-23121 and rated 9.8/10, to achieve unauthenticated remote code execution during the Pwn2Own 2021 hacking competition on a Western Digital PR4100 running the My Cloud OS firmware.

Three of the other bugs that QNAP warned its customers about received severity ratings of 9.8/10 (i.e., CVE-2022-23125, CVE-2022-23122, CVE-2022-0194), allowing unauthenticated attackers to execute arbitrary code remotely without requiring authentication on unpatched devices.

See also: QNAP: Serious Linux bug affects most NAS devices

On March 22, the Netatalk development team released version 3.1.13 to fix these security bugs, three months after the flaws were reported following the Pwn2Own contest.

QNAP says that the Netatalk vulnerabilities (fixed in QTS version 4.5.4.2012, build 20220419 and later) affect the following operating system versions:

  • QTS 5.0.x and later
  • QTS 4.5.4 and later version
  • QTS 4.3.6 and later version
  • QTS 4.3.4 and later version
  • QTS 4.3.3 and later version
  • QTS 4.2.6 and later version
  • QuTS hero h5.0.x and later
  • QuTS hero h4.5.4 and later
  • QuTScloud c5.0.x
QNAP: Disable AFP until we fix some important bugs

QNAP: Disable AFP until firmware is fixed

“QNAP is thoroughly investigating the case. We will release security updates for all affected QNAP operating system versions and provide more information as soon as possible,” the NAS manufacturer said.

“To mitigate these vulnerabilities, disable AFP. We recommend that users check back and install security updates as they become available.”

To disable AFP on your QTS or QuTS hero NAS device, you need to go to Control Panel > Network & File Services > Win/Mac/NFS/WebDAV > Apple Networking and select Disable AFP (Apple Filing Protocol).

See also: QNAP NAS: Forced firmware update for DeadBolt ransomware

QNAP is also working to address a Linux vulnerability called "Dirty Pipe" that is actively exploited in attacks that allows for root privileges to be acquired, and a high-severity OpenSSL bug that can lead to DoS situations and remote errors.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS