<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>QNAP Archives &#8211; ATYXIT - Illinois IT Services and IT Support</title>
	<atom:link href="https://atyxit.com/tag/qnap/feed/" rel="self" type="application/rss+xml" />
	<link>https://atyxit.com/tag/qnap/</link>
	<description>Illinois IT Services and IT Support</description>
	<lastBuildDate>Sun, 08 May 2022 01:05:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.4</generator>
	<item>
		<title>QNAP Released Firmware Patches</title>
		<link>https://atyxit.com/qnap-released-firmware-patches/</link>
		
		<dc:creator><![CDATA[atyxadmin]]></dc:creator>
		<pubDate>Sun, 08 May 2022 01:05:26 +0000</pubDate>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[chicago business IT]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[QNAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://atyxit.com/?p=207228</guid>

					<description><![CDATA[<p>QNAP, a Taiwan based provider of network-attached storage (NAS) devices announced security updates on Friday that address nine security weaknesses, including a critical issue that could be exploited to take over an affected system. &#8220;A vulnerability has been reported to affect QNAP VS Series NVR running QVR,&#8221; QNAP said in an advisory. &#8220;If exploited, this vulnerability allows [&#8230;]</p>
<p>The post <a href="https://atyxit.com/qnap-released-firmware-patches/">QNAP Released Firmware Patches</a> appeared first on <a href="https://atyxit.com">ATYXIT - Illinois IT Services and IT Support</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>QNAP, a Taiwan based provider of network-attached storage (NAS) devices announced security updates on Friday that address nine security weaknesses, including a critical issue that could be exploited to take over an affected system. </p>



<p>&#8220;A vulnerability has been reported to affect QNAP VS Series NVR running QVR,&#8221; QNAP <a href="https://www.qnap.com/en-in/security-advisory/qsa-22-07" target="_blank" rel="noreferrer noopener">said</a> in an advisory. &#8220;If exploited, this vulnerability allows remote attackers to run arbitrary commands.&#8221; As a result of this vulnerability, QNAP released firmware patches.  </p>



<p>Tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27588" target="_blank" rel="noreferrer noopener"><strong>CVE-2022-27588</strong></a> (CVSS score: 9.8), the vulnerability has been addressed in QVR 5.1.6 build 20220401 and later. Credited with reporting the flaw is the Japan Computer Emergency Response Team Coordination Center (<a href="https://www.jpcert.or.jp/english/" target="_blank" rel="noreferrer noopener">JPCERT/CC</a>).</p>



<p>Customers are encouraged to update their devices as soon as possible. In the event you need assistance updating your devices, don&#8217;t hesitate to <a href="https://atyxit.com/contact-us/" target="_blank" rel="noreferrer noopener">contact us</a> after reading about our <a href="https://atyxit.com/chicago-cyber-security/" target="_blank" rel="noreferrer noopener">Cybersecurity services</a>. </p>



<p>Aside from the critical shortcoming, QNAP has also resolved three high-severity and five medium-severity bugs in its software. Relevant CVE ID&#8217;s for the high and medium severities being addressed can be found below:</p>



<p> &#8211;</p>



<ul class="wp-block-list"><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38693" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-38693</strong></a>&nbsp;(CVSS score: 5.3) &#8211; A&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-13" rel="noreferrer noopener" target="_blank">path traversal vulnerability</a>&nbsp;in thttpd affecting QNAP devices running QTS, QuTS hero, QuTScloud, and QVR Pro Appliance, leading to information disclosure</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44051" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44051</strong></a>&nbsp;(CVSS score: 8.8) &#8211; A&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-16" rel="noreferrer noopener" target="_blank">command injection vulnerability</a>&nbsp;in QNAP devices running QTS, QuTS hero, and QuTScloud, resulting in arbitrary command execution</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44052" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44052</strong></a>&nbsp;(CVSS score: 6.5) &#8211; An&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-16" rel="noreferrer noopener" target="_blank">improper link resolution before file access (&#8220;link following&#8221;) vulnerability</a>&nbsp;in QNAP devices running QTS, QuTS hero, and QuTScloud, allowing attackers to read/write files in arbitrary file locations</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44053" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44053</strong></a>&nbsp;(CVSS score: 5.7) &#8211; A&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-16" rel="noreferrer noopener" target="_blank">cross-site scripting (XSS) vulnerability</a>&nbsp;in QNAP devices running QTS, QuTS hero, and QuTScloud, leading to code injection</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44054" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44054</strong></a>&nbsp;(CVSS score: 4.3) &#8211; An&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-16" rel="noreferrer noopener" target="_blank">open redirect vulnerability</a>&nbsp;in QNAP devices running QTS, QuTS hero, and QuTScloud, making it possible to redirect users to a rogue web pages</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44055" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44055</strong></a>&nbsp;(CVSS score: 5.3) &#8211; A&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-14" rel="noreferrer noopener" target="_blank">missing authorization vulnerability</a>&nbsp;in QNAP devices running Video Station, allowing attackers to access data or perform unauthorized actions</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44056" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44056</strong></a>&nbsp;(CVSS score: 7.1) &#8211; An&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-14" rel="noreferrer noopener" target="_blank">improper authentication vulnerability</a>&nbsp;in QNAP devices running Video Station, leading to system compromise</li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44057" rel="noreferrer noopener" target="_blank"><strong>CVE-2021-44057</strong></a>&nbsp;(CVSS score: 7.1) &#8211; An&nbsp;<a href="https://www.qnap.com/en-in/security-advisory/qsa-22-15" rel="noreferrer noopener" target="_blank">improper authentication vulnerability</a>&nbsp;in QNAP devices running Photo Station, leading to system compromise</li></ul>



<p></p>
<p>The post <a href="https://atyxit.com/qnap-released-firmware-patches/">QNAP Released Firmware Patches</a> appeared first on <a href="https://atyxit.com">ATYXIT - Illinois IT Services and IT Support</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
