Network-attached storage (NAS) specialist QNAP has disclosed and released fixes for two new vulnerabilities, one of them a zero-day discovered in early November. The Taiwanese company's coordinated disclosure of the issues with researchers at Unit 42 by Palo Alto Networks has, however, led to some confusion over the severity of the security problem. QNAP assigned CVE-2023-50358 a middling 5.8-out-of-10 severity score, the breakdown of which revealed it was classified as a high-complexity attack that would have a low impact if exploited successfully. Unit 42's assessment, on the other hand, was the polar opposite: "These remote code execution vulnerabilities affecting IoT devices exhibit a combination of low attack complexity and critical impact, making them an irresistible target for threat actors. As a result, protecting IoT devices against such threats is an urgent task." The German Federal Office for Information Security (BSI) also released an emergency alert today warning that successful exploits could lead to "major damage," encouraging users to apply patches quickly. At the time of writing, the National Vulnerability Database (NVD) is still working to assign the vulnerability an independent rating. Typically, command injection vulnerabilities that are easy to exploit tend to attract severity scores at the higher end of the scale, so it will be interesting to see what the NVD's score ends up being. According to Unit42's internet scans of vulnerable devices carried out in...
QNAP vulnerability disclosure ends up an utter shambles
The Register
·Connor Jones
·Published Feb 13, 2024
·Updated
Affected Software
1 affected component
QNAP QTS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses newly disclosed vulnerabilities in QNAP's QTS software, including a zero-day flaw.
2
What security implications are discussed in the article?
The vulnerabilities could potentially allow unauthorized access and data breaches for QNAP NAS devices.
3
What products or software are affected by these vulnerabilities?
The vulnerabilities specifically affect QNAP's QTS software used in their network-attached storage devices.
4
When were the vulnerabilities discovered?
One of the vulnerabilities was discovered in early November.
5
What has QNAP done in response to these vulnerabilities?
QNAP has released fixes for the vulnerabilities as part of their coordinated disclosure effort.