What are you looking for ?
Infinidat
Articles_top

Qnap: Resolved Vulnerability in QTS and QuTS hero NAS OS

Already fixed vulnerability in QTS 5.0.1.2234 build 20221201 and later, and QuTS hero h5.0.1.2248 build 20221215 and later NAS OS.

Qnap Systems, Inc. had published a security advisory concerning a resolved vulnerability in QTS and QuTS hero NAS OS.

Release date: January 30, 2023
Security ID: QSA-23-01
Severity: Critical
CVE identifier: CVE-2022-27596
Affected products: QTS 5.0.1, QuTS hero h5.0.1
Status: Resolved

Summary
A vulnerability has been reported to affect Qnap devices running QTS 5.0.1 and QuTS hero h5.0.1. If exploited, this vulnerability allows remote attackers to inject malicious code.

The company have already fixed this vulnerability in following OS versions:

  • QTS 5.0.1.2234 build 20221201 and later

  • QuTS hero h5.0.1.2248 build 20221215 and later

Recommendation
To secure
the device, the company recommend regularly updating the system to the latest version to benefit from vulnerability fixes. User can check the product support status to see the latest updates available to NAS model.

Updating QTS or QuTS hero

  1. Log in to QTS or QuTS hero as an administrator.

  2. Go to Control Panel > System > Firmware Update.

  3. Under Live Update, click Check for Update.
    QTS or QuTS hero downloads and installs the latest available update.

Tip: User can also download the update from the Qnap website. Go to Support > Download Center and then perform a manual update for specific device.

Attachment:

Acknowledgements: huasheng_mangguo

Revision history: V1.0 (January 30, 2023) – Published

Articles_bottom
AIC
ATTO
OPEN-E