QNAP QTS / QuTS Hero DEADBOLT Ransomware (QSA-22-02)

critical Nessus Plugin ID 159513

Synopsis

The remote host is missing a security update.

Description

The version of QNAP QTS / QuTS Hero installed on the remote host is affected by an arbitrary code execution vulnerability which is being actively exploited by the DEADBOLT ransomware. The ransomware encrypts files, renames them with a .deadbolt extension and hijacks the login page with a ransom note. An investigation conducted by QNAP established the ransomware is exploiting the vulnerability outlined in qsa-21-57.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in the QSA-22-02 advisory

See Also

https://www.qnap.com/en/security-advisory/qsa-22-02

https://www.qnap.com/en/security-advisory/qsa-21-57

Plugin Details

Severity: Critical

ID: 159513

File Name: qnap_qts_quts_hero_qsa-22-02.nasl

Version: 1.5

Type: combined

Family: Misc.

Published: 4/5/2022

Updated: 12/7/2022

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Score based on analysis of vulnerability

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:qnap:qts, cpe:/o:qnap:qts, cpe:/o:qnap:quts_hero

Patch Publication Date: 2/2/2022

Vulnerability Publication Date: 2/2/2022