ZeroHour
Security Affairspublished ()ingested @securityaffairs

QNAP fixed 3 flaws in its NAS devices, including an auth bypass

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21899
+1 in the same advisory: …21900
An improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

NVD description · AI analysis pending
9.8
group max
24%
  • qnap qts
  • qnap quts hero
  • qnap qutscloud
CVE-2024-21901
A SQL injection vulnerability has been reported to affect myQNAPcloud.

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: myQNAPcloud 1.0.52 ( 2023/11/24 ) and later QTS 4.5.4.2627 build 20231225 and later

NVD description · AI analysis pending
4.719%
  • qnap myqnapcloud
  • qnap qts
Full article212 words · extracted from securityaffairs.com · click to collapse

QNAP addressed three vulnerabilities in its NAS products that can be exploited to access devices.

QNAP addressed three vulnerabilities in Network Attached Storage (NAS) devices that can be exploited to access the devices.

The three flaws fixed are:

  • CVE-2024-21899: an improper authentication vulnerability could allow users to compromise the security of the system via a network.
  • CVE-2024-21900: an injection vulnerability could allow authenticated users to execute commands via a network.
  • CVE-2024-21901: an SQL injection vulnerability could allow authenticated administrators to inject malicious code via a network.

The vulnerability CVE-2024-21899 (CVSS score 9.8) is the most severe of the above issues, it can be exploited by an unauthenticated, remote attacker.

Below is the list of the vulnerable versions and the versions released by the Taiwanese vendor to address the issues:

Affected ProductFixed Version
QTS 5.1.xQTS 5.1.3.2578 build 20231110 and later
QTS 4.5.xQTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.xQuTS hero h5.1.3.2578 build 20231110 and later
QuTS hero h4.5.xQuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.xQuTScloud c5.1.5.2651 and later
myQNAPcloud 1.0.xmyQNAPcloud 1.0.52 (2023/11/24) and later

The advisory includes instructions for updating QTS, QuTS hero, QuTScloud, and myQNAPcloud.

Follow me on Twitter: @securityaffairs and Facebook

Pierluigi Paganini

(SecurityAffairs – hacking, NAS)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/160217/iot/qnap-nas-products-flaws.html