QNAP and Veritas dump 30-plus vulns over the weekend
ID: 25c7e92b-7878-5fc5-bd49-33090424cbe5
STIX ID: report--25c7e92b-7878-5fc5-bd49-33090424cbe5
Feed Name: The Register (Security)
QNAP released patches addressing 24 vulnerabilities across several NAS products—including two critical and multiple high-severity flaws that may allow code execution, privilege escalation, or data access—while also retracting and re-releasing a problematic firmware update; separately, Veritas disclosed seven critical deserialization vulnerabilities in Enterprise Vault (CVSSv3 9.8 preliminarily) that can lead to remote code execution via .NET Remoting, with mitigations available but full patches slated for a future major release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
