Article Details
Scrape Timestamp (UTC): 2023-11-06 16:56:13.340
Source: https://thehackernews.com/2023/11/qnap-releases-patch-for-2-critical.html
Original Article Text
Click to Toggle View
QNAP Releases Patch for 2 Critical Flaws Threatening Your NAS Devices. QNAP has released security updates to address two critical security flaws impacting its operating system that could result in arbitrary code execution. Tracked as CVE-2023-23368 (CVSS score: 9.8), the vulnerability is described as a command injection bug affecting QTS, QuTS hero, and QuTScloud. "If exploited, the vulnerability could allow remote attackers to execute commands via a network," the company said in an advisory published over the weekend. The shortcoming spans the below versions - Also fixed by QNAP is another command injection flaw in QTS, Multimedia Console, and Media Streaming add-on (CVE-2023-23369, CVSS score: 9.0) that could allow remote attackers to execute commands via a network. The following versions of the software are impacted - With QNAP devices exploited for ransomware attacks in the past, users running one of the aforementioned versions are urged to update to the latest version to mitigate potential threats. The development comes weeks after the Taiwanese company disclosed it took down a malicious server used in widespread brute-force attacks targeting internet-exposed network-attached storage (NAS) devices with weak passwords.
Daily Brief Summary
Taiwanese firm QNAP has issued security updates to rectify two significant flaws in its operating system that could result in arbitrary code execution.
The most critical vulnerability, tracked as CVE-2023-23368 with a CVSS severity score of 9.8, is a command injection vulnerability affecting QTS, QuTS hero, and QuTScloud.
If exploited, the vulnerability could allow remote hackers to execute commands via a network connection.
QNAP also addressed a similar command injection flaw (CVE-2023-23369, CVSS score: 9.0) in QTS, Multimedia Console, and Media Streaming add-on that could offer the same exploit route.
The issue was publicized in an advisory, urging users operating affected versions of the software to update to mitigate potential threats.
This security measure follows an announcement several weeks ago where QNAP reported taking down a malicious server used majorly for brute-force attacks against NAS devices with weak passwords.