Description:
QNAP has published security advisories to address multiple vulnerabilities in QNAP products. The list of patches can be found at:
https://www.qnap.com/en/security-advisory/qsa-24-28
https://www.qnap.com/en/security-advisory/qsa-24-32
https://www.qnap.com/en/security-advisory/qsa-24-33
Affected Systems:
- QNAP NAS devices running QTS operating system versions prior to 4.5.4.2790 build 20240605, 5.1.8.2823 build 20240712, 5.2.0.2782 build 20240601
- QNAP NAS devices running QuTS hero operating system versions prior to h4.5.4.2790 build 20240606, h5.1.8.2823 build 20240712, h5.2.0.2782 build 20240601
For detailed information of the affected systems, please refer to the corresponding security advisory at vendor's website.
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, elevation of privilege, information disclosure or security restriction bypass on an affected system.
Recommendation:
Patches for affected systems are available. System administrators of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
More Information:
- https://www.qnap.com/en/security-advisory/qsa-24-28
- https://www.qnap.com/en/security-advisory/qsa-24-32
- https://www.qnap.com/en/security-advisory/qsa-24-33
- https://www.hkcert.org/security-bulletin/qnap-nas-multiple-vulnerabilities_20240909
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34974
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34979
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39298
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21906
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-32763
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-32771
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38641