QNAP QTS / QuTS Hero Arbitrary Code Execution (QSA-21-57)

critical Nessus Plugin ID 159512

Synopsis

The remote host is missing a security update.

Description

The version of QNAP QTS / QuTS Hero installed on the remote host is affected by an arbitrary code execution vulnerability. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in the QSA-21-57 advisory

See Also

https://www.qnap.com/en/security-advisory/qsa-21-57

Plugin Details

Severity: Critical

ID: 159512

File Name: qnap_qts_quts_hero_qsa-21-57.nasl

Version: 1.5

Type: combined

Family: Misc.

Published: 4/5/2022

Updated: 10/5/2022

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Score based on analysis of vulnerability

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:qnap:qts, cpe:/o:qnap:quts_hero, cpe:/a:qnap:qts

Patch Publication Date: 1/13/2022

Vulnerability Publication Date: 1/13/2022