Skip to main content

QNAP NAS Remote Code Execution Vulnerability

Last Update Date: 12 Sep 2017 09:44 Release Date: 12 Sep 2017 3935 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in QNAP NAS with the Media Streaming Add-On installed. A user may gain access to the NAS and execute a malicious code without requiring any privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • All QNAP NAS currently or previously installed with the Media Streaming Add-On

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Install QTS 4.2.6 build 20170905 or QTS 4.3.3.0262 build 20170727
  • Then update the Media Streaming Add-on:
    QTS 4.3.x: Media Streaming Add-On 430.1.4.1 or later
    QTS 4.2.x: Media Streaming Add-On 421.1.1.1 or later

Vulnerability Identifier


Source


Related Link