New QNAP NAS Flaws Exploited In Recent Ransomware Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-36195 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-28799 | Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days. Do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices. | 9.8 | 78% | KEV ransomware |
| mass≈1M+ QNAP NAS devices plausibly run an affected HBS 3 build (the app ships bundled with the affected QTS/QuTS releases), with hundreds of thousands of QNAP NAS… |
Full article387 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 23, 2021
A new ransomware strain called "Qlocker" is targeting QNAP network attached storage (NAS) devices as part of an ongoing campaign and encrypting files in password-protected 7zip archives.
First reports of the infections emerged on April 20, with the adversaries behind the operations demanding a bitcoin payment (0.01 bitcoins or about $500.57) to receive the decryption key.
In response to the ongoing attacks, the Taiwanese company has released an advisory prompting users to apply updates to QNAP NAS running Multimedia Console, Media Streaming Add-on, and HBS 3 Hybrid Backup Sync to secure the devices from any attacks.
"QNAP strongly urges that all users immediately install the latest Malware Remover version and run a malware scan on QNAP NAS," the company said. "The Multimedia Console, Media Streaming Add-on, and Hybrid Backup Sync apps need to be updated to the latest available version as well to further secure QNAP NAS from ransomware attacks."
Patches for the three apps were released by QNAP over the last week. CVE-2020-36195 concerns an SQL injection vulnerability in QNAP NAS running Multimedia Console or Media Streaming Add-on, successful exploitation of which could result in information disclosure. On the other hand, CVE-2021-28799 relates to an improper authorization vulnerability affecting QNAP NAS running HBS 3 Hybrid Backup Sync that could be exploited by an attacker to log in to a device.
But it appears that Qlocker is not the only strain that's being used to encrypt NAS devices, what with threat actors deploying another ransomware named "eCh0raix" to lock sensitive data. Since its debut in July 2019, the eCh0raix gang is known for going after QNAP storage appliances by leveraging known vulnerabilities or carrying out brute-force attacks.
QNAP is also urging users to the latest version of Malware Remover to perform a scan as a safety measure while it's actively working on a solution to remove malware from infected devices.
"Users are advised to modify the default network port 8080 for accessing the NAS operating interface," the company recommended, adding "the data stored on NAS should be backed up or backed up again utilizing the 3-2-1 backup rule, to further ensure data integrity and security."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/new-qnap-nas-flaws-exploited-in-recent.html