Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager
ID: 0a9bb1a4-ab31-5ac3-a388-340c768ad19f
STIX ID: report--0a9bb1a4-ab31-5ac3-a388-340c768ad19f
Feed Name: The Hacker News
Threat Score
The report summarizes disclosed vulnerabilities in Kyocera Device Manager (CVE-2023-50916) — an authentication coercion/path traversal issue that can force authentication to attacker-controlled SMB/UNC paths enabling credential capture or NTLM relay — and multiple QNAP product flaws including prototype pollution, XSS, command injection, SQL injection, and an unauthenticated RCE; vendors have released patches and users are advised to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
