Article Details

Scrape Timestamp (UTC): 2024-11-05 09:39:28.756

Source: https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html

Original Article Text

Click to Toggle View

Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices. Taiwanese network-attached storage (NAS) appliance maker Synology has addressed a critical security flaw impacting DiskStation and BeePhotos that could lead to remote code execution. Tracked as CVE-2024-10443 and dubbed RISK:STATION by Midnight Blue, the zero-day flaw was demonstrated at the Pwn2Own Ireland 2024 hacking contest by security researcher Rick de Jager. RISK:STATION is an "unauthenticated zero-click vulnerability allowing attackers to obtain root-level code execution on the popular Synology DiskStation and BeeStation NAS devices, affecting millions of devices," the Dutch company said. The zero-click nature of the vulnerability means it does not require any user interaction to trigger the exploitation, thereby allowing attackers to gain access to the devices to steal sensitive data and plant additional malware. The flaw impacts the following versions - Additional technical details about the vulnerability have been currently withheld so as to give customers sufficient time to apply the patches. Midnight Blue said there are between one and two million Synology devices that are currently simultaneously affected and exposed to the internet. QNAP Patches 3 Critical Bugs The disclosure comes as QNAP resolved three critical flaws affecting QuRouter, SMB Service, and HBS 3 Hybrid Backup Sync, all of which were exploited during Pwn2Own - While there is no evidence that any of the aforementioned vulnerabilities have been exploited in the wild, users are advised to apply the patches as soon as possible given that NAS devices have been high-value targets for ransomware attacks in the past.

Daily Brief Summary

MALWARE // Synology Fixes Zero-Click RCE Vulnerability in NAS Devices

Synology, a Taiwanese NAS appliance maker, has patched a critical security flaw identified as CVE-2024-10443, impacting DiskStation and BeePhotos.

The zero-day flaw, named RISK:STATION, allows unauthenticated zero-click root-level code execution on millions of Synology NAS devices.

The vulnerability was exposed during the Pwn2Own Ireland 2024 hacking contest by security researcher Rick de Jager.

No user interaction is needed to exploit this flaw, significantly increasing the risk of unauthorized access, data theft, and further malware installation.

Between one and two million Synology devices connected to the internet are at risk due to this vulnerability.

Additional details about the flaw are withheld to allow time for users to apply the necessary patches.

Concurrently, QNAP addressed three critical vulnerabilities in different services, which were also highlighted during Pwn2Own.