Wednesday, November 29, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

ASUSTOR: Vulnerabilities in NAS operating system allow takeover

Eliza Houghton by Eliza Houghton
August 23, 2023
in World
0
ASUSTOR: Vulnerabilities in NAS operating system allow takeover
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

Asustor has reported five vulnerabilities in the NAS operating system Asustor Data Master (ADM), which the manufacturer closes with an updated version. The manufacturer classifies the gaps as high-risk. Anyone using Asustor NAS should therefore download and install the updates quickly.

Advertisement

Asustor: NAS devices can be attacked from the network

Unregistered attackers from the network can inject arbitrary commands due to insufficient filtering of the data transferred. Asustor does not want to explain how this works in the security notification, but instead mentions “unspecified attack vectors” (CVE-2023-2910, CVSS 8.8, risk “high”). The vulnerability is a hair’s breadth from being classified as “critical”.

Another vulnerability allows local users to change the configuration without authorization (CVE-2023-3699, CVSS 8.7, high). In the printer service, unauthenticated users from the network can navigate beyond the intended directory structures and create (CVE-2023-3697, CVSS 8.5, high) and delete (CVE-2023-3698, CVSS 8.5, high) files. In addition, malicious actors can abuse the file rename feature to move files to unintended directories (CVE-2023-4475, CVSS 7.5, high).

All security-related errors mentioned are corrected by the Asustor Data Master (ADM) update to version 4.2.3 RK91 or newer; ADM versions of the 4.0, 4.1 and 4.2 branches are affected. Asustor users should install the update quickly so as not to become victims of potential attacks.

To do this, administrators can activate Live Update, which notifies them of available updates when they log in, or set up automatic, scheduled updates that check for and install updates within the specified period. A manual update is possible with an ADM image that can be downloaded from the Asustor support website after specifying the device used.

In the past, vulnerabilities in Asustor firmware were attacked by the Deadbolt ransomware, among others.

Advertisement

(dmk)

Go to home page
#ASUSTOR #Vulnerabilities #NAS #operating #system #takeover

Tags: ADMAsustorAsustor Data MasterNASoperatingSecuritySecurity updatesSecurity VulnerabilitiessystemtakeoverUpdatesVulnerabilities
Previous Post

Drought causes ships to collapse in the Panama Canal

Next Post

Bonifacio de la Cuadra, the journalist who told it all

Eliza Houghton

Eliza Houghton

Related Posts

Amazon introduces Q: Generative AI for enterprise customers
World

Amazon introduces Q: Generative AI for enterprise customers

by Eliza Houghton
November 29, 2023
Bildarratz believes it is unjustified that EH Bildu goes “from a yes to a no” to the Education Law due to “a nuance”
World

Bildarratz believes it is unjustified that EH Bildu goes “from a yes to a no” to the Education Law due to “a nuance”

by Eliza Houghton
November 29, 2023
Marjane Satrapi, illustrator and filmmaker: “Iran is experiencing the world’s first feminist revolution”
World

Marjane Satrapi, illustrator and filmmaker: “Iran is experiencing the world’s first feminist revolution”

by Eliza Houghton
November 29, 2023
Ukraine: Five arrests in raid against ransomware gang
World

Ukraine: Five arrests in raid against ransomware gang

by Eliza Houghton
November 29, 2023
Watch football through a voice
World

Watch football through a voice

by Eliza Houghton
November 29, 2023
Next Post
Bonifacio de la Cuadra, the journalist who told it all

Bonifacio de la Cuadra, the journalist who told it all

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

Higher Regional Court: Cloudflare is liable as a perpetrator for copyright infringements

Higher Regional Court: Cloudflare is liable as a perpetrator for copyright infringements

November 7, 2023
The loss of the school year and the educational lag: the other devastation left by Hurricane ‘Otis’

The loss of the school year and the educational lag: the other devastation left by Hurricane ‘Otis’

November 18, 2023
Ukraine denounces the poisoning of the wife of the head of intelligence services

Ukraine denounces the poisoning of the wife of the head of intelligence services

November 28, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Software development Spain Sánchez Today Ukraine Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Software development Spain Sánchez Today Ukraine Updates Vulnerabilities war workshop world years

Recent Posts

  • Amazon introduces Q: Generative AI for enterprise customers
  • Bildarratz believes it is unjustified that EH Bildu goes “from a yes to a no” to the Education Law due to “a nuance”
  • Marjane Satrapi, illustrator and filmmaker: “Iran is experiencing the world’s first feminist revolution”
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.