QNAP Systems, headquartered in Taiwan, recently unveiled patches for various vulnerabilities impacting its product lineup, notably a critical-severity flaw facilitating unauthorized access to devices. Identified as CVE-2024-21899, with a CVSS score of 9.8, this vulnerability arises from improper authentication, potentially leading to system compromise through network access. This vulnerability affects QNAP's QTS, QuTS hero, and QuTScloud products, rendering network-attached storage (NAS) devices vulnerable to unauthorized entry. QuTS hero versions h5.1.3.2578 build 20231110 and h4.5.4.2626 build 20231225, and QuTScloud version c5.1.5.2651 all address the issue. Additionally, QNAP's advisory highlights two further vulnerabilities, tracked as CVE-2024-21900 and CVE-2024-21901, affecting QTS, QuTS hero, QuTScloud, and myQNAPcloud. These medium-severity issues could lead to command execution or code injection over a network. Exploiting both vulnerabilities requires authentication, with CVE-2024-21901 necessitating administrator credentials. Patches for these vulnerabilities are accessible in QTS versions 4.5.4.2627 build 20231225 and 5.1.3.2578 build 20231110, QuTS hero version h5.1.3.2578 build 20231110, QuTScloud version c5.1.5.2651, and myQNAPcloud version 1.0.52 (released on 2023/11/24). Moreover, QNAP has released patches for various other medium-severity vulnerabilities spanning QuMagie Mobile, QTS, QuTS hero, QuTScloud, and Photo Station, mitigating potential risks like code injection, command execution, and data leaks. No reported instances of these vulnerabilities being exploited in attacks have surfaced. For comprehensive details, consult QNAP's security advisories page. Renowned for its NAS and professional network video recorder (NVR) products, QNAP also offers an array of networking equipment.
A critical security issue in the Marimo Python notebook environment has raised serious alarm in the cybersecurity community due to its ability to enable unauthenticated remote comm...
A sophisticated software supply chain attack targeted the widely used Nx Console extension on the Microsoft Visual Studio Code Marketplace, potentially exposing more than two milli...
Critical security flaws have been discovered in the workflow automation platform n8n, prompting urgent warnings from cybersecurity researchers. The vulnerabilities, tracked as CVE-...