{"id":16804,"date":"2023-02-01T14:32:06","date_gmt":"2023-02-01T13:32:06","guid":{"rendered":"https:\/\/www.show.it\/30k-internet-exposed-qnap-nas-devices-affected-by-recent-vulnerability\/"},"modified":"2023-02-01T14:32:06","modified_gmt":"2023-02-01T13:32:06","slug":"30k-internet-exposed-qnap-nas-devices-affected-by-recent-vulnerability","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/30k-internet-exposed-qnap-nas-devices-affected-by-recent-vulnerability\/","title":{"rendered":"30k Internet-Exposed QNAP NAS Devices Affected by Recent Vulnerability"},"content":{"rendered":"<p><strong>Attack surface management firm Censys has identified roughly 30,000 internet-exposed QNAP network-attached storage (NAS) appliances that are likely affected by a recently disclosed critical-severity code injection vulnerability.<\/strong><\/p>\n<p>Tracked as CVE-2022-27596 (CVSS score of 9.8), the security defect is described as an SQL injection bug that <a href=\"https:\/\/www.securityweek.com\/critical-qnap-vulnerability-leads-to-code-injection\/\" target=\"_blank\" rel=\"noreferrer noopener\">allows remote attackers to inject malicious code<\/a> into vulnerable NAS devices.<\/p>\n<p>The issue impacts all devices that run QTS 5.0.1 and QuTS hero h5.0.1, and Censys says that<a href=\"https:\/\/censys.io\/cve-2022-27596\/\" target=\"_blank\" rel=\"noreferrer noopener\"> nearly 30,000 devices<\/a> running a vulnerable software version can be found on the internet.<\/p>\n<p>However, the number of affected devices could be much higher, the company warns. Censys has identified over 67,000 hosts that run QNAP software, but it could not retrieve the version information for 37,000 of them.<\/p>\n<p>Most of the identified vulnerable hosts are in Italy (3,200) and the US (3,149). Taiwan (1,942), Germany (1,881), and Japan (1,714) round up the top five list.<\/p>\n<p>\u201cIf the exploit is published and weaponized, it could spell trouble to thousands of QNAP users. Everyone must upgrade their QNAP devices immediately to be safe from future ransomware campaigns,\u201d Censys notes.<\/p>\n<p>QNAP appliances are known to be a target for cybercriminals, and the recent<a href=\"https:\/\/www.securityweek.com\/qnap-warns-new-deadbolt-ransomware-attacks-targeting-nas-users\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Deadbolt ransomware attacks<\/a> are proof of that. At its peak, the threat had infected over 20,000 devices, allowing cybercriminals to steal roughly $200,000 from victims.<\/p>\n<p>\u201cWhile there are no indications that bad actors are using this new exploit, the threat is definitely on the horizon,\u201d Censys underlines.<\/p>\n<p>QNAP has patched the vulnerability with the release of QTS 5.0.1.2234 build 20221201 and QuTS hero h5.0.1.2248 build 20221215. Users are advised to update their devices as soon as possible and to make sure that they are not accessible directly from the internet.<\/p>\n<p><strong>Related<\/strong>:<a href=\"https:\/\/www.securityweek.com\/qnap-patches-critical-vulnerability-network-surveillance-products\/\"> QNAP Patches Critical Vulnerability in Network Surveillance Products<\/a><\/p>\n<p><strong>Related<\/strong>:<a href=\"https:\/\/www.securityweek.com\/qnap-warns-nas-users-deadbolt-ransomware-attacks\/\"> QNAP Warns NAS Users of DeadBolt Ransomware Attacks<\/a><\/p>\n<p><strong>Related:<\/strong> \u2018<a href=\"https:\/\/www.securityweek.com\/raspberry-robin-windows-worm-abuses-qnap-devices\/\">Raspberry Robin\u2019 Windows Worm Abuses QNAP Devices<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/30k-internet-exposed-qnap-nas-devices-affected-by-recent-vulnerability\/\">30k Internet-Exposed QNAP NAS Devices Affected by Recent Vulnerability<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/\">SecurityWeek<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attack surface management firm Censys has identified roughly 30,000 internet-exposed QNAP network-attached storage (NAS) appliances that are likely affected by a recently disclosed critical-severity code injection vulnerability. Tracked as CVE-2022-27596 (CVSS score of 9.8), the security defect is described as an SQL injection bug that allows remote attackers to inject malicious code into vulnerable NAS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16805,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[44,148,23],"tags":[],"class_list":["post-16804","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iot-security","category-nas","category-vulnerabilities"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=16804"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16804\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/16805"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=16804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=16804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=16804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}