安全ID : NAS-201908-26

Security Advisory for Vulnerability in QTS and Photo Station


  • 发布日期 : August 26, 2019

  • 通用漏洞披露 : CVE-2019-7192 | CVE-2019-7193 | CVE-2019-7194 | CVE-2019-7195

  • 受影响产品: All QNAP NAS running QTS 4.4.1 build 20190807, QTS 4.3.6 build 20190724, and earlier versions. All QNAP NAS running Photo Station versions:
    ● 5.2.10 and earlier in QTS 4.2.6
    ● 5.4.8 and earlier in QTS 4.3.3
    ● 5.7.9 and earlier in QTS 4.3.4
    ● 6.0.1 and earlier in QTS 4.4.1

严重程度

Important

状态

已解决


Summary

Multiple vulnerabilities have been reported to affect versions of QTS and Photo Station. If exploited, these vulnerabilities may allow an attacker to access or modify paths and files used in system operations, or execute arbitrary code on the system and gain unauthorized access to data.

We have already fixed these issues in the following software versions.
QTS:

  • QTS 4.4.1: build 20190816 and later
  • QTS 4.3.6: build 20190813 and later

Photo Station:

  • QTS 4.2.6: Photo Station 5.2.11 and later
  • QTS 4.3.3: Photo Station 5.4.9 and later
  • QTS 4.3.4: Photo Station 5.7.10 and later
  • QTS 4.4.1: Photo Station 6.0.2 and later

Recommendation

To fix these vulnerabilities, we recommend updating QTS and Photo Station to their latest versions.

Installing the QTS Update

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.
    Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating Photo Station

  1. Log on to QTS as administrator.
  2. Open the App Center, and then click .
    A search box appears.
  3. Type “Photo Station”, and then press ENTER.
    The Photo Station application appears in the search results list.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if you are using the latest version.
  5. Click OK.
    The application is updated.

 

致谢: Henry Huang from CyCarrier CSIRT

修订历史: V1.0 (September 6, 2019) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top