QNAP fixes CVE-2024-50388 that’s exploited in Pwn2Own Ireland

QNAP fixes CVE-2024-50388 that’s exploited in Pwn2Own Ireland


QNAP has addressed a critical zero-day vulnerability in its HBS 3 Hybrid Backup Sync software, following its successful exploitation at the recent Pwn2Own Ireland 2024 competition.

The vulnerability, tracked as CVE-2024-50388 with a CVSS score of 7.8, allowed to execute arbitrary commands on a QNAP TS-464 NAS device, highlighting the potential for serious security breaches.

The exploit was showcased by Ha The Long and Ha Anh Hoang of Viettel Cyber Security (@vcslab), who leveraged an OS command injection flaw to compromise the NAS device. They earned $10,000 prize and 4 Master of Pwn points.

Advertisements

QNAP acknowledged and emphasized that it could allow remote attackers to gain unauthorized access and control of vulnerable systems and released HBS 3 Hybrid Backup Sync version 25.1.1.673, which effectively patches the flaw.

The update process is straightforward and can be completed within QTS or QuTS hero by following these steps:

  1. Log in as an administrator.
  2. Open App Center and click the search icon.
  3. Type “HBS 3 Hybrid Backup Sync” and press Enter.
  4. Click Update next to the HBS 3 Hybrid Backup Sync app.
  5. Confirm the update by clicking OK.

For more details refer to the blog

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.