Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2023-133
Version:
1.0
Affected software:
CVE-2023-23368 affected QTS versions:
CVE-2023-23369 affected QTS versions:
• 4.3.3
• 4.3.4
• 4.3.6
• 5.1.x
• Media Streaming add-on 500.1.x and 500.0.x
• Multimedia Console 2.1.x and 1.4.x
• QTS 5.0.x and 4.5.x
• QuTS hero h5.0.x and h4.5.x
• QuTScloud c5.0.1.
Type:
Command injection vulnerabilities
CVE/CVSS:
CVE-2023-23368: CVSS 9.8(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVE-2023-23369: CVSS 9.0(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
https://nvd.nist.gov/vuln/detail/CVE-2023-23368
https://nvd.nist.gov/vuln/detail/CVE-2023-23369
QNAP Systems published security advisories for two critical command injection vulnerabilities that impact multiple versions of the QTS operating system and applications on its network-attached storage (NAS) devices.
The first flaw is being tracked as CVE-2023-23368 and has a critical severity rating of 9.8 out of 10. It is a command injection vulnerability that a remote attacker can exploit to execute commands via a network.
The second vulnerability is identified as CVE-2023-23369 and has a lower severity rating of 9.0 and could also be exploited by a remote attacker to the same effect as the previous one.
Both the vulnerabilities have a HIGH Impact on Confidentiality, Integrity, and Availability. No user Interaction Is required to exploit these vulnerabilities.
The two vulnerabilities (CVE-2023-23368 and CVE-2023-23369) affects several QNAP operating systems versions. When exploited, the vulnerabilities could allow users to execute commands via a network.
Since the QNAP operating system Is used on NAS devices that are typically used to store data, command execution flaws could have a serious impact as cybercriminals are often looking for new targets to steal and/or encrypt sensitive data from.
The Centre for Cyber Security Belgium strongly recommends system administrators to take the following actions:
For CVE-2023-23368, fixes are available in the following releases:
For CVE-2023-23369, fixes are available in the following releases:
https://www.bleepingcomputer.com/news/security/qnap-warns-of-critical-command-injection-flaws-in-qts-os-apps/
https://therecord.media/qnap-urgently-fixing-vulnerabilities-in-systems