CERT India Reports QNAP Product Vulnerabilities
ID: c23be978-a301-54df-84ba-163ecd566719
STIX ID: report--c23be978-a301-54df-84ba-163ecd566719
Feed Name: Cyble Blog
CERT-In published an advisory describing multiple high-severity vulnerabilities in QNAP QTS and QuTS Hero (affecting versions such as QTS 5.1.0.2823, QTS hero h5.1.0.2823, QTS 4.5.4.2790, QTS hero h4.5.4.2790, QuTS h5.2.0.2782 and earlier) that may enable remote code execution, privilege escalation, authentication bypass, heap-based buffer overflows and data exposure; the advisory lists seven CVEs (CVE-2023-34974, CVE-2023-34979, CVE-2023-39298, CVE-2024-21906, CVE-2024-32763, CVE-2024-32771, CVE-2024-38641) and urges immediate patching and mitigation to protect enterprise NAS deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
