ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10443
Unauthenticated OS Command Injection RCE in Synology Photos and BeePhotos

CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation.

Do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction.

9.828%
  • Synology Photos all versions before 1.6.2-0720 (1.6.x line) and before 1.7.0-0795 (1.7.x line)
  • Synology BeePhotos all versions before 1.0.2-10026 (1.0.x line) and before 1.1.0-10053 (1.1.x line)
massmillions of NAS devices (press reports cite millions of vulnerable Synology DiskStation and BeePhotos units)
CVE-2024-50387
A SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later

NVD description · AI analysis pending
10.010%
  • qnap smb service
CVE-2024-50388
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

NVD description · AI analysis pending
9.52%
  • qnap hybrid backup sync
CVE-2024-50389
A SQL injection vulnerability has been reported to affect QuRouter.

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

NVD description · AI analysis pending
9.5<1%
  • qnap qurouter
Full article347 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 05, 2024Vulnerability / Data Security

Taiwanese network-attached storage (NAS) appliance maker Synology has addressed a critical security flaw impacting DiskStation and BeePhotos that could lead to remote code execution.

Tracked as CVE-2024-10443 and dubbed RISK:STATION by Midnight Blue, the zero-day flaw was demonstrated at the Pwn2Own Ireland 2024 hacking contest by security researcher Rick de Jager.

RISK:STATION is an "unauthenticated zero-click vulnerability allowing attackers to obtain root-level code execution on the popular Synology DiskStation and BeeStation NAS devices, affecting millions of devices," the Dutch company said.

The zero-click nature of the vulnerability means it does not require any user interaction to trigger the exploitation, thereby allowing attackers to gain access to the devices to steal sensitive data and plant additional malware.

The flaw impacts the following versions -

Additional technical details about the vulnerability have been currently withheld so as to give customers sufficient time to apply the patches. Midnight Blue said there are between one and two million Synology devices that are currently simultaneously affected and exposed to the internet.

QNAP Patches 3 Critical Bugs

The disclosure comes as QNAP resolved three critical flaws affecting QuRouter, SMB Service, and HBS 3 Hybrid Backup Sync, all of which were exploited during Pwn2Own -

  • CVE-2024-50389 - Fixed in QuRouter 2.4.5.032 and later
  • CVE-2024-50387 - Fixed in SMB Service 4.15.002 and SMB Service h4.15.002, and later
  • CVE-2024-50388 - Fixed in HBS 3 Hybrid Backup Sync 25.1.1.673 and later

While there is no evidence that any of the aforementioned vulnerabilities have been exploited in the wild, users are advised to apply the patches as soon as possible given that NAS devices have been high-value targets for ransomware attacks in the past.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html