HomeSecurityQNAP patches critical command injection vulnerabilities in QTS OS

QNAP patches critical command injection vulnerabilities in QTS OS

QNAP is patching two critical command injection vulnerabilities affecting multiple versions of the QTS operating system and applications on network-attached storage (NAS ) devices .

QNAP QTS

The first vulnerability (CVE-2023-23368) has been rated 9.8/10 and is considered critical. It is a command injection vulnerability, which can be exploited by a remote attacker to execute commands over a network.

The QTS versions affected by the vulnerability are QTS 5.0.x and 4.5.x, QuTS hero h5.0.x and h4.5.x, and QuTScloud c5.0.1.

The fixes are available in the following versions:

  • QTS 5.0.1.2376 build 20230421 and later
  • QTS 4.5.4.2374 build 20230416 and later
  • QuTS hero h5.0.1.2376 build 20230421 and later
  • QuTS hero h4.5.4.2374 build 20230417 and later
  • QuTScloud c5.0.1.2374 and later

The second vulnerability (CVE-2023-23369), which QNAP patched, has a rating of 9.0/10 and could also be used by a remote attacker to execute commands.

See also: Veeam patches serious vulnerabilities in Veeam ONE

The affected QTS versions are: 5.1.x, 4.3.6, 4.3.4, 4.3.3 and 4.2.x, Multimedia Console 2.1.x and 1.4.x and Media Streaming add-on 500.1.x and 500.0.x.

Corrections are available at:

  • QTS 5.1.0.2399 build 20230515 and later version
  • QTS 4.3.6.2441 build 20230621 and later version
  • QTS 4.3.4.2451 build 20230621 and later version
  • QTS 4.3.3.2420 build 20230621 and later version
  • QTS 4.2.6 build 20230621 and later
  • Multimedia Console 2.1.2 (2023/05/04) and newer version
  • Multimedia Console 1.4.8 (2023/05/05) and newer version
  • Media Streaming add-on 500.1.1.2 (2023/06/12) and newer version
  • Media Streaming add-on 500.0.0.11 (2023/06/16) and newer version

To update QTS, QuTS hero, and QuTScloud, administrators can log in and go to Control Panel > System > Firmware Update and click “Check for Update” in the Live Update area. There, they can download and install the latest version. Updates are also available as manual downloads from the QNAP website.

Updating the Multimedia Console is possible by searching for the installation in the App Center and clicking the “Update” button (available only if a newer version is available). The process is similar for updating the Media Streaming add-on.

See also: The new CVSS 4.0 vulnerability severity rating standard has just been released

command injection vulnerabilities
QNAP patches critical command injection vulnerabilities in QTS OS

Since QNAP NAS devices are commonly used for data, these types of vulnerabilities, which the company has now patched, could have a serious impact. Cybercriminals are often looking for new targets to steal and/or encrypt sensitive data. Attackers can then demand a ransom from the victim to keep the data or to decrypt it.

QNAP NAS device users are urged to apply available security updates as soon as possible.

The potential risks of these vulnerabilities are serious and should be taken seriously. A command injection vulnerability allows malicious code to be executed on the system . This can lead to the disclosure of sensitive information, such as passwords or personal data. In addition, the malicious code can cause damage to the system, by deleting or modifying files or even violating network security

See also: “Hello Kitty” Ransomware: Exploited Vulnerability in Open Source Apache ActiveMQ

Additionally, command injection vulnerabilities can be used to perform remote attacks, such as executing malicious code or installing malware on other devices on the network.

Finally, vulnerabilities can affect a company's credibility and reputation. If vulnerabilities are not fixed promptly, they can damage a company's image and reduce customer and user.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS