QNAP: NAS manufacturer warns of critical vulnerability

VG word pixels

security breach

The company QNAP, which primarily appears as a NAS manufacturer, is struggling with a particularly serious security gap. This should now be fixed – an update is strongly recommended.

News

Qnap TS-233 in review
QNAP NAS devices should be updated in a timely manner.
© QNAP / Montage: PC Magazine

The NAS manufacturer QNAP is affected by a critical vulnerability that allows attackers to use relatively simple means to install malicious code via the respective NAS devices. Due to the ease of access to the relevant devices and the potential severity of exploitation, the vulnerability identified as CVE-2022-27596 has a CVSS score of 9.8 and is therefore considered serious.

In concrete terms, cybercriminals can use the vulnerability to penetrate the NAS system with a few targeted attacks without the user having to interact in any way. According to QNAP, the gap itself occurs in the firmware versions QTS 5.0.1 and QuTS Hero h5.0.1.

It is not yet known whether the vulnerability has been actively exploited. QNAP itself already has an update on its official website made available, which should fix the vulnerability. According to the company, this should be installed on any NAS devices as soon as possible in order to protect the respective servers.

To update to the secure firmware version, users must log in to QTS or QuTS Hero as an administrator. Via the path “Control Panel” > “System” > “Firmware Update” you get to the menu item “Live Update”. Here you will find the “Check for update” function, with which QNAP automatically finds and installs the current update, which is supposed to fix the CVE-2022-27596 vulnerability.

Stylized padlock next to the inscription

“checkmate”

QNAP warns of ransomware attacks on NAS devices

The ransomware “Checkmate” is currently attacking NAS devices from QNAP. In addition to a warning, QNAP also offers hints and tips to protect against the attacks.

Four 2-bay NAS systems under test

2-bay NAS system

Four 2-bay NAS systems in the test: QNAP, Synology & Co.

We looked at four 2-bay NAS devices, each suited to different tasks or needs, and accordingly they have four…

31.1.2023 from
Yusuf Hatic

Continue to home page

more on the subject

Synology NAS: Security compromised

Brute force attack and ransomware – update

Synology and QNAP NAS at Risk: Security Tips for…

The NAS manufacturers Synology and QNAP report attacks on their network hard drives. With the following safety tips you are well prepared.

Stylized padlock next to the inscription

Video surveillance and NAS

QNAP closes critical security gap

QNAP has closed security gaps for NAS and video surveillance. One vulnerability was even classified as “critical”.

Stylized padlock next to the inscription

“checkmate”

QNAP warns of ransomware attacks on NAS devices

The ransomware “Checkmate” is currently attacking NAS devices from QNAP. In addition to a warning, QNAP also offers hints and tips to protect against the attacks.

CPU socket on a motherboard
Credit card phishing

Beware of fake mails

Disney+ subscription phishing attempt

The consumer centers warn of phishing attempts on Disney + subscribers. Fake emails are circulating, demanding sensitive customer information.

Reference-www.pc-magazin.de