Tuesday, March 28, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Qnap-NAS: Critical vulnerability allows malicious code to be injected

Kiratas by Kiratas
January 30, 2023
in World
Reading Time: 1 min read
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

With updated firmware, Qnap closes a critical security gap in network storage devices with QTS and QuTS hero operating systems. Attackers could inject and execute their own code through the vulnerability, the company explains.

Any further details on the vulnerability are missing from Qnap’s security advisory. However, the security-related error affects the NAS operating systems QTS 5.0.1 and QuTS hero h5.0.1. The manufacturer classifies the severity as critical a, with a CVSS score of 9.8.

The CVE entry for the vulnerability has been given the number CVE-2022-27596. The CVE entry notes that the vulnerability is due to insufficient filtering of specific elements used in an SQL command. The explanation is based on the scheme of the Common Weakness Enumeration (CWE), the vulnerability type has been given the number CWE-89. The security notification also does not name a specific attack vector for how malicious actors can exploit the vulnerability.

Qnap NAS: Updates

The updates to version QTS 5.0.1.2234 Build 20221201 such as QuTS hero h5.0.1.2248 Build 20221215 should stop the security leak. Administrators can find these by searching for their NAS model on Qnap’s support status website.

Alternatively, administrators can also search for the firmware update directly on the affected devices in the Control Panel under “System”-“Firmware Update” under “Live Update” by clicking on “Check for Update” and have it installed immediately. Qnap recently attracted attention due to a critical vulnerability in the optionally installable component Photo Station, through which the DeadBolt ransomware spread.

(dmk)

To home page

Tags: CodeCriticalinjectedmaliciousNASQNAPQnapNASSecuritySecurity UpdatesupdateVulnerabilitiesvulnerability

Related Posts

World

The shameful video of Gerard Piqué with his children: criticism rains down on him for the stupidity he has done in public

by Kiratas
March 28, 2023
World

The ‘Café’ of the Observatory, the space for analysis, dialogue and dissemination of the ”la Caixa” Foundation

by Kiratas
March 28, 2023
World

Visit to Beijing: Tim Cook praises Apple’s “symbiotic relationship” with China

by Kiratas
March 28, 2023
World

Like an elephant’s trunk: soft robotic arm for collaborative work

by Kiratas
March 28, 2023
World

Gerard Piqué humiliates Shakira by hitting him where it hurts the most: his children, in the middle of everything

by Kiratas
March 28, 2023
Next Post

One for all: Linux distribution blendOS mixes Arch, Fedora and Ubuntu

Mazón will ask the Supreme Court for the suspension of Sánchez's plan that dries up the orchard of Europe

One for all: Linux distribution blendOS mixes Arch, Fedora and Ubuntu

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • The shameful video of Gerard Piqué with his children: criticism rains down on him for the stupidity he has done in public
  • The ‘Café’ of the Observatory, the space for analysis, dialogue and dissemination of the ”la Caixa” Foundation
  • Visit to Beijing: Tim Cook praises Apple’s “symbiotic relationship” with China
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.