SMBs: Qnap NAS systems at risk

B2B Cyber ​​Security ShortNews

Share post

The well-known NAS manufacturer QNAP reports two highly dangerous vulnerabilities in its network products and another vulnerability in its VPN device client for Windows. A remote attack is possible through the gaps - suitable patches are available.

The vulnerabilities announced by QNAP affect many applications used within the network products. The services also operate and work in large NAS systems for the SME sector. Therefore, in addition to smaller, privately used NAS systems or cameras, many company products are also affected by the security gaps.

Remote takeover for DoS attack possible

QNAP reports that a vulnerability related to uncontrolled resource consumption affects several QNAP operating systems. If the vulnerability is exploited, remote users can launch a denial of service (DoS) attack. The vulnerability is listed as CVE-2022-27600. The exact CVSS value is not known, but must be in the range of 7.0 to 8.9 for Highly Dangerous.

The vulnerability has already been fixed in the following versions that are available for update:

  • QTS 5.0.1.2277 Build 20230112 and later
  • QTS 4.5.4.2280 Build 20230112 and later
  • QuTS hero h5.0.1.2277 build 20230112 and later
  • QuTS hero h4.5.4.2374 build 20230417 and later
  • QuTScloud c5.0.1.2374 build 20230419 and later
  • QVR Pro Appliance 2.3.1.0476 and later

Another vulnerability in the QVPN Device Client

Furthermore, QNAP reports a vulnerability in its QVPN Device Client for Windows. The vulnerability is also considered highly dangerous under CVE-2022-27595. There, loading libraries is insecure and may affect devices running the QVPN Device Client for Windows. If exploited, this vulnerability could allow locally authenticated users to execute code by insecurely loading the library. The QVPN Device Client for macOS, Android and iOS is not affected by the vulnerability.

An update is also available for this gap:

QVPN Device Client for Windows, version 2.0.0.1316 and higher

More at QNAP.com

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more