HomeUpdatesQNAP fixed critical vulnerabilities in various products

QNAP has fixed critical vulnerabilities in various products

QNAP has fixed several security vulnerabilities, including three critical bugs, which users should address as soon as possible.

QNAP vulnerabilities

Two of the vulnerabilities affect QNAP Notes Station 3, a note-taking and collaboration application used on the company's NAS systems:

CVE-2024-38643 (CVSS v4:9.3, “critical”): Lack of authentication for critical functions could allow remote attackers to gain unauthorized access and perform specific system functions. Without proper authentication mechanisms, attackers can exploit the vulnerability without prior credentials and compromise the system.

See also: XSS vulnerability in Bing allows malicious requests

CVE-2024-38645 : Server-side request forgery (SSRF) vulnerability , which could allow remote attackers with authentication credentials to send specially crafted requests that manipulate server-side behavior. This could potentially expose sensitive application data.

QNAP has patched the two vulnerabilities in version 3.9.7. Update instructions are available in this bulletin. Immediate application of the update is recommended.

Two other serious vulnerabilities are CVE-2024-38644 and CVE-2024-38646, which allow command injection and unauthorized data access, but require user-level access to exploit.

Vulnerabilities in QNAP QuRouter

The third critical vulnerability fixed by QNAP is CVE-2024-48860 , which affects QuRouter 2.4.x products. With a CVSS v4 score of 9.5, it could allow remote attackers to execute commands on the host system.

QNAP has also patched a second, less severe OS command injection vulnerability, CVE-2024-48861. Both vulnerabilities are fixed in QuRouter version 2.4.3.106.

See also: 7-Zip vulnerability allows hackers to execute arbitrary code

QNAP has fixed critical vulnerabilities in various products

QNAP: Fixing vulnerabilities in other products as well

Other products that received significant fixes are QNAP AI Core (AI engine), QuLog Center (log management tool), QTS (standard operating system for NAS devices), and QuTS Hero (advanced version of QTS).

The most serious of these vulnerabilities are CVE-2024-38647 (in QNAP AI Core, fixed in version 3.4.1 and later) CVE-2024-48862 (affects versions 1.7.x and 1.8.x of QuLog Center and fixed in versions 1.7.0.831 and 1.8.0.888), CVE-2024-50396, CVE-2024-50397 (fixed in QTS 5.2.1.2930 and QuTS hero h5.2.1.2929).

These vulnerabilities allow access to sensitive data (the last three also allow data modification).

QNAP customers are advised to install updates as soon as possible to stay safe. Regularly checking for updates and applying them in a timely manner can significantly reduce exposure to these security risks. In addition, QNAP recommends implementing other security measures, such as using strong passwords, enabling firewalls, and using VPNs to further enhance device security.

See also: NVIDIA Base Command Manager vulnerability allows remote code execution

QNAP takes security seriously and regularly conducts assessments to proactively identify potential risks. Users can stay up-to-date on the latest updates and security announcements by watching QNAP's security bulletins or following their social media channels.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS