安全ID : QSA-21-24
Inclusion of Sensitive Information in QSS
发布日期 : June 11, 2021
通用漏洞披露 : CVE-2021-28805
受影响产品: Certain QNAP Switches
严重程度
Important
状态
已解决
Summary
Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data.
We have already fixed this vulnerability in the following versions:
- QSW-M2108-2C: QSS 1.0.3 build 20210505 and later
- QSW-M2108-2S: QSS 1.0.3 build 20210505 and later
- QSW-M2108R-2C: QSS 1.0.3 build 20210505 and later
- QSW-M408: QSS 1.0.12 build 20210506 and later
Recommendation
To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes.
Updating QSS
- Log on to QSS.
- Go to System > Firmware Update > Live Update.
- Click Check for Update.
QSS checks for available firmware updates. - Click Update System.
A confirmation message appears. - Click Update. QSS downloads and installs the latest available update.
Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.
致谢: Jan Hoff
修订历史: V1.0 (June 11, 2021) - Published