ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical vulnerabilities open Synology, QNAP NAS devices to attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-31439
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager.

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12326.

NVD description · AI analysis pending
8.82%
  • synology diskstation manager
  • synology debian linux
  • synology netatalk
CVE-2022-23121
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15819.

NVD description · AI analysis pending
9.89%
  • netatalk netatalk
  • netatalk debian linux
Full article388 words · extracted from helpnetsecurity.com · click to collapse

Users of Synology and QNAP network-attached storage (NAS) devices are advised to be on the lookout for patches for several critical vulnerabilities affecting Netatalk, an open-source implemention of the Apple Filing Protocol (AFP) that allows Unix-like operating systems to serve file servers for Macs.

There is no indication that they are currently being exploited by attackers in the wild, but until patches are made available, users should implement mitigations delineated by the companies.

About the Netatalk vulnerabilities

Network-attached storage (NAS) devices are usually used by small-to-medium businesses and home users for storing and sharing files and backups. Also, they are often exposed to the public internet, making them also reachable to attackers.

Vulnerabilities affecting some of the most widely used NAS devices are often exploited to covertly mine cryptocurrency or are compromised, their contents stolen or encrypted and held for ransom.

The vulnerabilities that are currently the problem were reported and some of them exploited at the Pwn2Own 2021 hacking competition.

They have been patched in Netatalk v3.1.1 in March, but the new version has yet to be propagated to some of the affected devices.

They vulnerabilities in question are:

  • CVE-2022-0194, CVE-2022-23122, and CVE-2022-23125, which can be exploited to achieve unauthenticated remote code execution
  • CVE-2022-23123 and CVE-2022-23124 – two sensitive information disclosure vulnerabilities
  • CVE-2022-23121 and CVE-2021-31439, two vulnerabilities that may allow network-adjacent attackers to execute arbitrary code on affected installations

Patches and mitigation advice

Western Digital reacted earlier this year, before the Netatalk update with fixes, by removing Netatalk from their firmware altogether. “Users can continue to access local network shares and perform Time Machine backup via SMB,” they said.

TrueNAS has fixed the issues in TrueNAS Core 12.0-U8.1, released earlier this month.

Synology says that they are in the process of pushing out fixes – there’s one for Synology DiskStation Manager v7.1 out already – and that users who want immediate assistence to mitigate the risk of exploitation should contact the company’s technical support service.

QNAP has fixed the vulnerabilities on QTS 4.5.4.2012 build 20220419 and later and is working on other fixes. In the meantime, they advise users to temporarily disable the AFP (which can be done through the devices’ control panel, under the Network & File Services tab) and to implement updates as soon as they are available.

Asustor is working on fixes.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/04/29/nas-devices-vulnerabilities/