Hurry up, disable AFP on your QNAP NAS until the vendor fixes 8 bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-31439 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12326. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2022-23121 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15819. NVD description · AI analysis pending | 9.8 | 9% |
| — |
Full article404 words · extracted from securityaffairs.com · click to collapse

QNAP urges customers to disable the AFP file service protocol on their NAS devices until it fixes critical Netatalk flaws.
Taiwanese vendor QNAP is warning customers to disable the AFP file service protocol on their network-attached storage (NAS) deviced until it fixes several critical Netatalk vulnerabilities.
Netatalk is a free, open-source implementation of the Apple Filing Protocol that allows Unix-like operating systems to serve as a file server for macOS computers. QNAP NAS devices support the AFP protocol to enable macOS users to access data on the NAS.
“Upon the latest release of Netatalk 3.1.13, the Netatalk development team disclosed multiple fixed vulnerabilities affecting earlier versions of the software: CVE-2021-31439, CVE-2021-31439, CVE-2022-23121, CVE-2022-23123, CVE-2022-23122, CVE-2022-23125, CVE-2022-23124, and CVE-2022-0194.” reads the advisory published by the vendor. “To mitigate these vulnerabilities, disable AFP. We recommend users to check back and install security updates as soon as they become available”
The Netatalk maintainers released version 3.1.13 to fix these flaws on March 22.
The vulnerabilities affect the following operating system versions:
- QTS 5.0.x and later
- QTS 4.5.4 and later
- QTS 4.3.6 and later
- QTS 4.3.4 and later
- QTS 4.3.3 and later
- QTS 4.2.6 and later
- QuTS hero h5.0.x and later
- QuTS hero h4.5.4 and later
- QuTScloud c5.0.x
The company has announced it has already addressed the vulnerabilities in QTS 4.5.4.2012 build 20220419 and later.
Administrators can disable AFP on their QTS or QuTS hero NAS devices through Control Panel > Network & File Services > Win/Mac/NFS/WebDAV > Apple Networking and select the Disable AFP item.
In Mid-March, the Taiwanese hardware vendor QNAP warned most of its Network Attached Storage (NAS) devices are impacted by the recently discovered Linux vulnerability ‘Dirty Pipe.’
An attacker with local access can exploit the high-severity vulnerability Dirty Pipe to gain root privileges.
The vendor has yet to fix the Dirty Pipe flaw on NAS devices running QuTScloud c5.0.x. The vendor released firmaware updates to solve critical Apache HTTP Server issues for devices running QTS, QuTS hero, and QuTScloud.
Please vote for Security Affairs as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog” and others of your choice.
To nominate, please visit: https://docs.google.com/forms/d/e/1FAIpQLSfxxrxICiMZ9QM9iiPuMQIC-IoM-NpQMOsFZnJXrBQRYJGCOw/viewform
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, AFP)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/130720/hacking/critical-afp-qnap-nas.html