QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices. Rsync is an open-source file synchronization tool that supports direct file syncing via its daemon, SSH transfers via SSH, and incremental transfers that save time and bandwidth. It's widely used by many backup solutions like Rclone, DeltaCopy, and ChronoSync, as well as in cloud and server management operations and public file distribution. The flaws are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leak via uninitialized stack), CVE-2024-12086 (server leaks arbitrary client files), CVE-2024-12087 (path traversal via --inc-recursive option), CVE-2024-12088 (bypass of --safe-links option), and CVE-2024-12747 (symbolic link race condition). QNAP says they affect HBS 3 Hybrid Backup Sync 25.1.x, the company's data backup and disaster recovery solution, which supports local, remote, and cloud storage services. In a security advisory released on Thursday, QNAP said it addressed these vulnerabilities in HBS 3 Hybrid Backup Sync 25.1.4.952 and advised customers to update their software to the latest version. To update the Hybrid Backup Sync installation on your NAS device, you will have to: These Rsync flaws can be combined to create exploitation chains that lead to remote system compromise. The attackers only require anonymous read access to vulnerable servers. "When combined, the first two vulnerabil...
QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
BleepingComputer
·Sergiu Gatlan
·Published Jan 23, 2025
·Updated
Affected Software
2 affected components
QNAP HBS 3 Hybrid Backup Sync=25.1.x
QNAP HBS 3 Hybrid Backup Sync=25.1.x
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses QNAP addressing six vulnerabilities in their HBS 3 Hybrid Backup Sync application.
2
What security implications are discussed in the article?
The vulnerabilities could allow attackers to execute remote code on unpatched QNAP NAS devices.
3
What products are affected by the vulnerabilities?
The affected product is QNAP HBS 3 Hybrid Backup Sync, specifically version 25.1.x.
4
Why is it important for QNAP users to update their software?
Updating is crucial to prevent potential unauthorized access and remote code execution due to these vulnerabilities.
5
How can users protect their NAS devices from exploitation?
Users should apply the latest patches provided by QNAP for their HBS 3 software to mitigate the risks.