安全ID : NAS-201803-23

Security Advisory for Vulnerabilities in QTS


  • 发布日期 : March 23, 2018

  • 通用漏洞披露 : CVE-2017-7629 | CVE-2017-7630 | CVE-2017-7631 | CVE-2017-7632

  • 受影响产品: QTS 4.2.6: build 20171026 and earlier versions
    QTS 4.3.3: build 20170727 and earlier versions

严重程度

Important

状态

已解决


Summary

Four vulnerabilities affecting different versions of QTS have recently been reported. Below are details for each CVE. 

  • CVE-2017-7629: This vulnerability allows any QTS user to bypass password verification steps when changing their own password.
  • CVE-2017-7630: This vulnerability allows remote attackers to access sensitive information on the NAS.
  • CVE-2017-7631: This cross-site scripting (XSS) vulnerability allows remote attackers to inject malicious code in the compromised application.
  • CVE-2017-7632:  This cross-site scripting (XSS) vulnerability allows remote attackers to inject malicious code in the compromised application.

We have already fixed these issues in the following QTS versions.

  • QTS 4.2.6: build 20171208 and later
  • QTS 4.3.3: build 20170901 and later

Recommendation

To fix these vulnerabilities, you must update QTS to the following versions.

  • QTS 4.2.6: build 20171208 or later
  • QTS 4.3.3: build 20170901 or later

Installing the QTS Update

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.

Tip: You can also download the update from the QNAP website. Go to Support > Download and then perform a manual update.

 

致谢: Tony Martin, information security researcher

修订历史: V1.0 (March 23, 2018) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top