New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Critical QNAP NAS vulnerability fixed, update your device ASAP! (CVE-2022-27596)

New York Tech Editorial Team by New York Tech Editorial Team
January 31, 2023
in Cybersecurity
0
Critical QNAP NAS vulnerability fixed, update your device ASAP! (CVE-2022-27596)
Share on FacebookShare on Twitter

QNAP Systems has fixed a critical vulnerability (CVE-2022-27596) affecting QNAP network-attached storage (NAS) devices, which could be exploited by remote attackers to inject malicious code into a vulnerable system.

CVE-2022-27596

Luckily for QNAP NAS owners, there’s no mention of it being exploited by attackers or an exploit being publicly available.

About CVE-2022-27596

QNAP’s advisory does not offer more details about CVE-2022-27596, but the vulnerability entry in NIST’s National Vulnerability Database reveals that the flaw may allow attackers to execute an SQL injection attack, due to “improper neutralization of special elements used in an SQL command.”

Successful exploitation may allow attackers to access sensitive data, modify or delete it.

The vulnerability affects QNAP devices running version 5.0.1 of the QTS operating system for entry- and mid-level QNAP NAS devices and versions h5.0.1 of QuTS hero, the OS for high-end and enterprise QNAP NAS models. It has been fixed in:

  • QTS 5.0.1.2234 build 20221201 and later
  • QuTS hero h5.0.1.2248 build 20221215 and later

Protect your NAS

“SQL injection has become a common issue with database-driven web sites. The flaw is easily detected, and easily exploited, and as such, any site or software package with even a minimal user base is likely to be subject to an attempted attack of this kind,” MITRE points out.

QNAP NAS devices (and other widely used NAS devices) are often targeted by threat actors wielding different flavors of ransomware. They sometimes exploit zero-day vulnerabilities to load the malware onto vulnerable internet-facing devices, but don’t mind exploiting known vulnerabilities and relying on many users not updating their devices regularly.

No workarounds for this flaw are available and QNAP advises users to update their appliances immediately.

Aside from that, administrators of NAS devices should:

  • Use a unique, complex and long password and multi-factor authentication to secure the device’s admin account from password-guessing and brute-force attacks
  • Disallow access to the device from the internet (if it’s not needed) and perhaps limit access to it only from a specific IP range (e.g., their home or business network).

Credit: Source link

Previous Post

Here’s a last look at new Samsung Galaxy S23 leaks before the event

Next Post

Buy now, pay later leading CEE fintech service Mokka enters Bulgaria

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Buy now, pay later leading CEE fintech service Mokka enters Bulgaria

Buy now, pay later leading CEE fintech service Mokka enters Bulgaria

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026
Arito founding team

Arito AI Raises $6 Million To Bring Agentic Intelligence To Finance And Revenue Teams

May 20, 2026
Viewz founding team

Viewz Raises $7M to Retire the Finance Stack as We Know It

May 19, 2026
graphic design of hand holding a phone

Blings Turns Marketing Videos Into a Single-Line AI Input

May 12, 2026
two men discussing

The VC Model Is Broken, Says Omri Hurwitz In His Latest IsraelTech Appearance

May 7, 2026
atoms logo

Atoms AI Is Changing How Businesses Launch and Grow — Fast

May 3, 2026

Recommended

graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026
Arito founding team

Arito AI Raises $6 Million To Bring Agentic Intelligence To Finance And Revenue Teams

May 20, 2026
Viewz founding team

Viewz Raises $7M to Retire the Finance Stack as We Know It

May 19, 2026
graphic design of hand holding a phone

Blings Turns Marketing Videos Into a Single-Line AI Input

May 12, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media