Thursday, November 30, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

ASUSTOR: Vulnerabilities in NAS operating system allow takeover

Eliza Houghton by Eliza Houghton
August 23, 2023
in World
0
ASUSTOR: Vulnerabilities in NAS operating system allow takeover
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Asustor has reported five vulnerabilities in the NAS operating system Asustor Data Master (ADM), which the manufacturer closes with an updated version. The manufacturer classifies the gaps as high-risk. Anyone using Asustor NAS should therefore download and install the updates quickly.

Advertisement

Asustor: NAS devices can be attacked from the network

Unregistered attackers from the network can inject arbitrary commands due to insufficient filtering of the data transferred. Asustor does not want to explain how this works in the security notification, but instead mentions “unspecified attack vectors” (CVE-2023-2910, CVSS 8.8, risk “high”). The vulnerability is a hair’s breadth from being classified as “critical”.

Another vulnerability allows local users to change the configuration without authorization (CVE-2023-3699, CVSS 8.7, high). In the printer service, unauthenticated users from the network can navigate beyond the intended directory structures and create (CVE-2023-3697, CVSS 8.5, high) and delete (CVE-2023-3698, CVSS 8.5, high) files. In addition, malicious actors can abuse the file rename feature to move files to unintended directories (CVE-2023-4475, CVSS 7.5, high).

All security-related errors mentioned are corrected by the Asustor Data Master (ADM) update to version 4.2.3 RK91 or newer; ADM versions of the 4.0, 4.1 and 4.2 branches are affected. Asustor users should install the update quickly so as not to become victims of potential attacks.

To do this, administrators can activate Live Update, which notifies them of available updates when they log in, or set up automatic, scheduled updates that check for and install updates within the specified period. A manual update is possible with an ADM image that can be downloaded from the Asustor support website after specifying the device used.

In the past, vulnerabilities in Asustor firmware were attacked by the Deadbolt ransomware, among others.

Advertisement

(dmk)

Go to home page
#ASUSTOR #Vulnerabilities #NAS #operating #system #takeover

Tags: ADMAsustorAsustor Data MasterNASoperatingSecuritySecurity updatesSecurity VulnerabilitiessystemtakeoverUpdatesVulnerabilities
Previous Post

Peronism and the center-right seek to realign after the coup of the primaries in Argentina and the victory of Milei

Next Post

A tree falls on the Paseo de Sarasate in Pamplona without causing injuries

Eliza Houghton

Eliza Houghton

Related Posts

iX workshop: flexible and convenient programming with GitHub Actions
World

iX workshop: flexible and convenient programming with GitHub Actions

by Eliza Houghton
November 30, 2023
Leonor de Borbón at the opening of the legislature: what are the pendants she wears and who designed her green dress
World

Leonor de Borbón at the opening of the legislature: what are the pendants she wears and who designed her green dress

by Eliza Houghton
November 30, 2023
Ordinary online advertising ends up next to porn, sodomy and in Iran thanks to Google
World

Ordinary online advertising ends up next to porn, sodomy and in Iran thanks to Google

by Eliza Houghton
November 30, 2023
Google reaches an agreement with Canada to compensate the media with almost 75 million dollars a year
World

Google reaches an agreement with Canada to compensate the media with almost 75 million dollars a year

by Eliza Houghton
November 30, 2023
Have you had problems reading EL PAÍS through the application on your iPhone?  We explain why (and we apologize, of course)
World

Have you had problems reading EL PAÍS through the application on your iPhone? We explain why (and we apologize, of course)

by Eliza Houghton
November 30, 2023
Next Post
A tree falls on the Paseo de Sarasate in Pamplona without causing injuries

A tree falls on the Paseo de Sarasate in Pamplona without causing injuries

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

From attacks to crime in the shadows: the Mafia reorganizes after the death of boss Messina Denaro

From attacks to crime in the shadows: the Mafia reorganizes after the death of boss Messina Denaro

September 30, 2023
Mexico’s controversial “alien bodies” undergo testing

Mexico’s controversial “alien bodies” undergo testing

September 20, 2023
Success in the first Open Day in the port of Palma

Success in the first Open Day in the port of Palma

September 30, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Software development Spain Sánchez Today Ukraine Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Software development Spain Sánchez Today Ukraine Updates Vulnerabilities war workshop world years

Recent Posts

  • iX workshop: flexible and convenient programming with GitHub Actions
  • Leonor de Borbón at the opening of the legislature: what are the pendants she wears and who designed her green dress
  • Ordinary online advertising ends up next to porn, sodomy and in Iran thanks to Google
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.