Site icon TheCyberThrone

QNAP Fixes multiple Vulnerabilities in its product

Advertisements

QNAP has warned customers to install firmware updates that fix five security vulnerabilities affecting its NAS devices. These vulnerabilities could allow attackers to execute commands, launch denial-of-service attacks.

CVE-2023-23362 : QNAP discovered an OS command injection vulnerability of high severity. When exploited, this vulnerability grants authenticated users the capability to execute commands over the network.

Affected Versions are given below:

Advertisements

CVE-2023-23358 & CVE-2023-23359: QNAP uncovered two out-of-bounds write vulnerabilities. Once exploited, these allow authenticated users to initiate a DoS attack over the network.

CVE-2023-23360 & CVE-2023-23361: QNAP has discovered two NULL pointer dereference vulnerabilities have also been reported, again potentially leading to DoS attacks via the network.

Versions Affected by DoS Vulnerabilities:

QNAP strongly advises its customers for timely system updates, ensuring you reap the benefits of vulnerability fixes.

Exit mobile version