phpBB Heb

Main Menu

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce

phpBB Heb

Header Banner

phpBB Heb

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce
PHP Scripting Language
Home›PHP Scripting Language›QNAP Releases Fix for RCE Security Vulnerability Affecting PHP in NAS Drive Management

QNAP Releases Fix for RCE Security Vulnerability Affecting PHP in NAS Drive Management

By George T. Sprague
June 22, 2022
0
0

QNAP NAS devices are vulnerable to another security threat. However, the company has released a patch. QNAP urges all NAS drive owners to update their devices to the latest firmware to stay protected. Incidentally, owners who do not change critical security settings are currently immune.

Even as QNAP tries to deal with ech0raix ransomware, another old vulnerability threatens QNAP NAS devices. The vulnerability exists in PHP, which is essentially a server scripting language involved in managing web pages and several backend processes. The problem seems to be in the part of PHP that deals with FPM (FastCGI Process Manager).

The PHP FPM security vulnerability can potentially allow attackers to write data remotely by blowing past pre-allocated buffers. If attackers can write to the space reserved for FCGI protocol data, they can easily perform remote code execution (RCE). Simply put, attackers can gain RCE privileges on an affected QNAP storage device.

The bug affects the following QNAP NAS enclosures:

  • QTS 5.0.x and later
  • QTS 4.5.x and later
  • QuTS hero h5.0.x and later
  • QuTS hero h4.5.x and later
  • QuTScloud c5.0.x and later

QNAP fixed the security vulnerability in QTS 5.0.1.2034 build 20220515 and later, as well as QuTS hero h5.0.0.2069 build 20220614 and later.

It is worrying that the security flaw has been known for three years. However, since it was not “workable”, it was not addressed. It looks like there could be new exploits in the wild that rely on this vulnerability. Therefore, QNAP may have released an update for its popular products.

QNAP recommends users update to the latest firmware as soon as possible to stay protected against the vulnerability rated as “very serious”. Updates can be pulled from QNAP’s official online database by going to Control Panel > System > Firmware Update, using the live update panel, or downloading an update file. directly from the QNAP website.

QNAP’s PSIRT team updated the original advisory and mentioned that devices with default configurations are not affected by the PHP FPM security vulnerability.

Source: Computer beeping

Related posts:

  1. Pay what you want to earn expert Python training courses with this bundle
  2. What is headless commerce and why is it prevalent in the world of e-commerce?
  3. How to write your first PHP code
  4. PHP Project Says A Security Issue Is Likely Due To A Main Database Leak

Recent Posts

  • A high country paradise for sockeye salmon | Alaska Science Forum
  • How to Choose the Best Tech Stack for Your Startup in 2022
  • Open Source to commercial software, the process from project to product
  • 5G services expected to be rolled out within a month, says MoS Telecom
  • 3 ways every business can get started with an open source software strategy

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020

Categories

  • Commerce
  • Internet Forum
  • Online Communities
  • Open Source Software
  • PHP Scripting Language
  • Terms and Conditions
  • Privacy Policy