安全ID : QSA-25-16
Multiple Vulnerabilities in File Station 5
发布日期 : June 7, 2025
通用漏洞披露 : CVE-2025-22484 | CVE-2025-22490 | CVE-2025-29871 | CVE-2025-29872 | CVE-2025-29873 | CVE-2025-29876 | CVE-2025-29877 | CVE-2025-33035 | CVE-2025-30279 | CVE-2025-33031
受影响产品: File Station 5 version 5.5.x
严重程度
Important
状态
已解决
Summary
Multiple vulnerabilities have been reported to affect File Station 5:
- CVE-2025-22484, CVE-2025-29872: Allocation of resources without limits or throttling vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to prevent other systems, applications, or processes from accessing the same type of resource. - CVE-2025-22490, CVE-2025-29873, CVE-2025-29876, CVE-2025-29877: NULL pointer dereference vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to launch a denial-of-service (DoS) attack. - CVE-2025-29871: Out-of-bounds read vulnerability
If a local attacker gains access to an administrator account, they can then exploit the vulnerability to obtain secret data. - CVE-2025-33035: Path traversal vulnerability
If a remote attacker gains access to a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. - CVE-2025-30279, CVE-2025-33031: Improper certificate validation vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to compromise the security of the system.
We have already fixed the vulnerabilities in the following version:
Affected Product | Fixed Version |
File Station 5 version 5.5.x | File Station 5 version 5.5.6.4847 and later |
Recommendation
To fix the vulnerabilities, we recommend updating File Station 5 to the latest version.
Updating File Station 5
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "File Station 5" and then press ENTER.
File Station 5 appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your File Station 5 is already up to date. - Click OK.
The system updates the application.
附件
- CVE-2025-22484.json
- CVE-2025-22490.json
- CVE-2025-29871.json
- CVE-2025-29872.json
- CVE-2025-29873.json
- CVE-2025-29876.json
- CVE-2025-29877.json
- CVE-2025-30279.json
- CVE-2025-33031.json
- CVE-2025-33035.json
致谢: coral
修订历史:
V1.0 (June 07, 2025) - Published