Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Fake Clickjacking Bug Bounty Reports: The Key Facts cyber security news
  • Crypto Exchanges Are Trading Against Their Customers Often – Regulation Bitcoin News bitcoin news
  • Argentinian Senate Passes Bill That Would Tax Assets Held in Foreign Countries, Including Crypto – Regulation Bitcoin News bitcoin news
  • Researchers Expose Inner Working of Billion-Dollar Wizard Spider Cybercrime Gang cyber security news
  • How The Tether Peg Could Predict Raging Bitcoin Volatility bitcoin news
  • ‘It’s Hard Not to Want to Be Long Crypto’ – Featured Bitcoin News bitcoin news
  • This Analyst Believes Ethereum May Lose 80% Of Its Value bitcoin news
  • Bitcoin Downtrend Intact, Why The Bears Might Aim $32K bitcoin news

QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available

Posted on May 2, 2022 By root No Comments on QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available


QNAP Advises

Network-attached storage (NAS) appliance maker QNAP on Wednesday said it’s working on updating its QTS and QuTS operating systems after Netatalk last month released patches to contain seven security flaws in its software.

Netatalk is an open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like operating systems to serve as file servers for Apple macOS computers.

On March 22, 2022, its maintainers released version 3.1.13 of the software to resolve major security issues — CVE-2021-31439, CVE-2022-23121, CVE-2022-23122, CVE-2022-23123, CVE-2022-23124, CVE-2022-23125, and CVE-2022-0194 — that could be exploited to achieve arbitrary code execution.

Network-attached storage

“This vulnerability [CVE-2022-23121] can be exploited remotely and does not need authentication,” NCC Group researchers noted last month. “It allows an attacker to get remote code execution as the ‘nobody’ user on the NAS. This user can access private shares that would normally require authentication.”

QNAP noted that the Netatalk vulnerabilities impact the following operating system versions –

  • QTS 5.0.x and later
  • QTS 4.5.4 and later
  • QTS 4.3.6 and later
  • QTS 4.3.4 and later
  • QTS 4.3.3 and later
  • QTS 4.2.6 and later
  • QuTS hero h5.0.x and later
  • QuTS hero h4.5.4 and later, and
  • QuTScloud c5.0.x
CyberSecurity

Until the updates are available, the Taiwanese company is recommending users to disable AFP. The flaws have been patched so far in QTS 4.5.4.2012 build 20220419 and later.

The disclosure arrives less than a week after QNAP said it’s investigating its product lineup for potential impact arising from two security vulnerabilities that were addressed in the Apache HTTP server last month.

Update: In an independent advisory published on Thursday, Synology confirmed that some of its products, including Synology DiskStation Manager (DSM) and Synology Router Manager (SRM), are impacted by the Netatalk flaws –

  • DSM 7.1 (Upgrade to 7.1-42661-1 or above)
  • DSM 7.0
  • DSM 6.2
  • VS Firmware 2.3, and
  • SRM 1.2





TheHackersNews/

cyber security news

Post navigation

Previous Post: Uzbekistan President Issues Decree Regulating Cryptocurrencies, Mining and Trading – Regulation Bitcoin News
Next Post: Experts Detail 3 Hacking Teams Working Under the Umbrella of TA410 Group

Related Posts

  • New Saitama backdoor Targeted Official from Jordan’s Foreign Ministry cyber security news
  • Web Trackers Caught Intercepting Online Forms Even Before Users Hit Submit cyber security news
  • CISA Urges Organizations to Patch Actively Exploited F5 BIG-IP Vulnerability cyber security news
  • Researchers Warn of “Eternity Project” Malware Service Being Sold via Telegram cyber security news
  • Cloudflare Thwarts Record DDoS Attack Peaking at 15 Million Requests Per Second cyber security news
  • Everything you need to know to create a Vulnerability Assessment Report cyber security news

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • U.S. Warns Against North Korean Hackers Posing as IT Freelancers cyber security news
  • Bored Ape’s Land Sale Broke Ethereum. Extreme Success Or Roaring Failure? bitcoin news
  • Ethereum Recovers But ETH Must Clear This Key Resistance bitcoin news
  • Ethereum Takes Hit, Why ETH Could Plunge Below $2,700 bitcoin news
  • Bitcoin Carnage Continues As BTC Disintegrates To $34K bitcoin news
  • BTC Slips to 10-Month Low, Below $33,000 – Market Updates Bitcoin News bitcoin news
  • APE Takes A Beating As It Sheds 50% Of Its Price bitcoin news
  • Finder’s Fintech Specialists Predict XRP Jumping to $2.55 by December 2022 – Markets and Prices Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme