安全ID : NAS-201802-01

Security Advisory for Dnsmasq Vulnerabilities in Container Station


  • 发布日期 : February 1, 2018

  • 通用漏洞披露 : CVE-2017-14491 | CVE-2017-14492 | CVE-2017-14493 | CVE-2017-14494 | CVE-2017-14495 | CVE-2017-14496 | CVE-2017-13704

  • 受影响产品: Container Station versions 1.7.2502 and earlier

严重程度

严重

状态

已解决


Summary

A number of Dnsmasq vulnerabilities have been discovered in Container Station. If exploited, these security issues may expose NAS devices using Container Station versions 1.7.2502 and earlier to possible remote code execution or denial-of-service attacks. They may also allow attackers to access sensitive information.

We have already patched these vulnerabilities in Container Station version 1.7.2569.

Recommendation

To resolve the issue, you must update Container Station to version 1.7.2569.

If you are using any of the following NAS models, you do not need to update Container Station since they already have the latest version:

  • TS-128A
  • TS-228A

Upgrading to Container Station 1.7.2569

  1. Log on to QTS as administrator.
  2. Open the App Center, and then click the Search icon.
    A search box appears.
  3. Type “Container Station”, and then press ENTER.
    The Container Station application appears in the search results list.
  4. Click Update.
    A confirmation message appears.
  5. Click OK.
    The application is updated.

修订历史: V1.0 (February 01, 2018) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top