Saturday, October 12, 2024
HomeCVE/vulnerabilityQNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges and Inject Malicious Code

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges and Inject Malicious Code

Published on

Malware protection

QNAP, the maker of network-attached storage (NAS) appliances, has recently released a warning statement that its products might be vulnerable to recent Linux vulnerabilities that could be exploited to gain access to the affected systems.

The vulnerability has been tracked as CVE-2022-0847, and this security flaw is a high severity flaw. Due to this critical vulnerability, several QNAP products are affected, and here they are:-

  • All QNAP x86-based NAS
  • Some QNAP ARM-based NAS running QTS 5.0.x and QuTS hero h5.0.x

Here is what the company stated:-

- Advertisement - SIEM as a Service

“A local privilege escalation vulnerability, also known as “dirty pipe,” has been reported to affect the Linux kernel on QNAP NAS running QTS 5.0.x and QuTS hero h5.0.x. If exploited, this vulnerability allows an unprivileged user to gain administrator privileges and inject malicious code.”

Flaw Profile

  • CVE identifier: CVE-2022-0847
  • Summary: Local Privilege Escalation Vulnerability in Linux (Dirty Pipe)
  • Security ID: QSA-22-05
  • Severity: High
  • CVSS score: 7.8
  • Release date: March 14, 2022
  • Not affected products: QNAP NAS running QTS 4.x
  • Status: Under investigation

By exploiting this vulnerability, an attacker could be able to overwrite arbitrary data into read-only files in the Linux kernel and access all the vulnerable systems.

As of February 23, 2022, three days after this flaw was reported to the Linux kernel security team, the problem has been fixed in the following Linux versions:-

  • Linux version 5.16.11
  • Linux version 5.15.25
  • Linux version 5.10.102

While if we talk about the security recommendations, then at this moment, there is no fix or mitigation is available for this security flaw. The cybersecurity experts of QNAP have recommended users stay tuned for security updates.

QNAP has asserted that they are closely and actively working with their security experts to publish the security updates as soon as possible.

Apart from this, as soon as possible, QNAP will release a security update and provide further information about the vulnerability since they are thoroughly investigating the vulnerability.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Foxit PDF Reader Vulnerability Let Attackers Execute Arbitary Code

Researchers recently disclosed six new security vulnerabilities across various software, as one critical vulnerability...

Multiple VMware NSX Vulnerabilities Let Attackers Gain Root Access

VMware has disclosed multiple vulnerabilities in its NSX product line that could potentially allow...

CISA Warns of Fortinet & Ivanti Vulnerabilities Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities...