Several critical security flaws discovered in Qnap network storage server software, cyber authorities sound alert


Alexandre Boero

Clubic news manager

May 13, 2024 at 12:19 p.m.

4

The TS-216G NAS from the manufacturer Qnap © Qnap

The TS-216G NAS from the manufacturer Qnap © Qnap

French cyber agencies and authorities are warning of critical security vulnerabilities in various Qnap products. Corrected, the flaws affected network attached storage (NAS) server software.

The Taiwanese company Qnap, specializing in network storage products, has just had serious security concerns, with several major vulnerabilities in its solutions. The problem is also serious enough for Cybermalveillance.gouv.fr to launch, this Monday, May 13, 2024, a CyberAlert, a system intended to raise awareness among individuals, communities and businesses of a critical flaw. So what happened and how can you avoid being exposed to cyber risk?

Qnap NAS server software hit by major vulnerabilities

In recent weeks, multiple vulnerabilities have been identified in Qnap products. Several network attached storage (NAS) server software from the brand have been exposed to cyber risk, presenting flaws of a certain severity, which can go up to the “high” threshold, even “critical” for one of them. ‘between them. Here is the list of affected systems:

  • QTS 5.x, 4.5.x
  • QuTS hero h5.x, h4.5.x
  • QuTScloud c5.x
  • myQNAPcloud 1.0.x
  • myQNAPcloud Link 2.4.x
  • Media Streaming Add-on 500.1.x.

Cyber ​​authorities, including ANSSI, the National Information Systems Security Agency, specify that these vulnerabilities could lead a malicious individual to take remote control of the equipment concerned. The risks of theft, espionage or even destruction of confidential data are also very real.

Only one way to protect yourself: update

Hackers can easily exploit these various vulnerabilities and risks, such as breach of data confidentiality, remote arbitrary code execution and security policy circumvention, to carry out massive attacks against systems today. ‘now vulnerable.

The company, which has since corrected these, now invites all people and entities who use its software and servers to update them as quickly as possible.

Best antivirus, comparison in May 2024
To discover
Best antivirus, comparison in May 2024

Apr 30, 2024 at 3:05 p.m.

Service comparisons

Sources: Cybermalveillance.gouv.fr, ANSSI

Alexandre Boero

Clubic news manager

Clubic news manager

Journalist, responsible for Clubic news. Reporter, videographer, host and even singer-imitator, I wrote my first article in 6th grade. I made this vocation my profession (graduated from the EJC...

Read other articles

Journalist, responsible for Clubic news. Reporter, videographer, host and even singer-imitator, I wrote my first article in 6th grade. I made this vocation my profession (graduated from EJCAM, a school recognized by the profession), to write, interview, film, edit and produce written, audio or video content on a daily basis. Some chemistry with Tech, certainly, but also with the world of media, sport and travel. In addition to journalism, video production and animation, I have a YouTube channel (in my name) which should pique your curiosity if you like beautiful walks around the world, new technologies and music 🙂

Read other articles





Source link -99