AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

QNAP: critical intervention to resolve security flaws in NAS

Urgent security measures: QTS, QuTS hero and QuTScloud updated to counter serious threats

QNAP has released updates to fix two serious vulnerabilities in its NAS devices, which could allow attackers to execute commands. It is urgent to install these updates.

This pill is also available in Italian language

QNAP Systems has released security alerts highlighting two relevant command injection vulnerabilities, affecting multiple versions of QTS, QuTS hero and QuTScloud firmware on its network-attached storage (NAS) devices. Cyber security analyst Pierluigi Paganini highlighted the seriousness of the threats that these flaws represent.

Identification and risk of security flaws

Identified with the code CVE-2023-23368, the first vulnerability obtains a score of 9.8, classifying it among the critical risk issues. A malicious user can exploit this flaw to execute unauthorized commands over the network. The second vulnerability, marked CVE-2023-23369 and with a severity score of 9.0, poses a similarly high risk.

Corrective measures for QNAP NAS

It is a priority for users of affected QNAP NAS devices to promptly apply security updates provided by the company. These updates are essential to preclude attack by malicious agents who have previously conducted malware campaigns aimed at exploiting outdated firmware versions of QNAP NAS.

Update information and procedures

Network administrators should check the device management interface, under the firmware update section, for the availability of new releases and proceed to download and install the most updated versions to mitigate the risk. The Multimedia Console and Media Streaming add-on components also need to be checked and updated via the device's App center. Finally, experts suggest avoiding paying ransoms in the event of attacks, as this does not guarantee resolution of the data compromise.

Follow us on Facebook for more pills like this

11/07/2023 21:10

Editorial AI

Last pills

Serious vulnerability discovered in Rabbit R1: all user data at riskVulnerability in Rabbit R1 exposes sensitive API keys. What are the privacy risks?

Cyber attack in Indonesia: the new Brain Cipher ransomware brings services to their kneesNew ransomware hits Indonesia: learn how Brain Cipher crippled essential services and the techniques used by hackers

Patelco Credit Union: security incident halts customer services in CaliforniaService disruption and customer frustration: Patelco Credit Union works to resolve security incident

Cyber attack on TeamViewer: immediate response and investigations underwayStrengthened security measures and international collaborations to counter the cyber threat