安全ID : QSA-21-17

Vulnerability in Roon Server


  • 发布日期 : May 14, 2021

  • 通用漏洞披露 : CVE-2021-28810 | CVE-2021-28811

  • 受影响产品: QNAP NAS running Roon Server

严重程度

严重

状态

已解决


Summary

The QNAP security team has detected an attack campaign in the wild related to a vulnerability in Roon Server. QNAP NAS running the following versions of Roon Server may be susceptible to attack:


  • Roon Server 2021-02-01 and earlier

Roon Labs has already fixed this vulnerability in the following versions:


  • Roon Server 2021-05-18 and later

Recommendation

To fix the vulnerability, we recommend updating Roon Server to the latest version.


Updating Roon Server

  1. Log on to QTS or QuTS hero as administrator.
  2. Open the App Center and then click .
    A search box appears.
  3. Type “Roon Server” and then press ENTER.
    Roon Server appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your version is already up to date.
  5. Click OK.
    The application is updated.

致谢: Beijing Venustech Cybervision Co. Ltd

修订历史:
V2.1 (June 8, 2021) - Update CVE ID and Acknowledgements
V2.0 (June 4, 2021) - Issue Resolved
V1.0 (May 14, 2021) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top