QNAP.QTS.Remote.Code.Injection

description-logoDescription

This indicates an attack attempt to exploit an Remote Command Injection vulnerability in QNAP QTS.
The vulnerability is due to improper sanitization of multiple components in HTTP requests. A remote attacker could exploit this vulnerability by sending crafted requests to the target system.

affected-products-logoAffected Products

QNAP QTS prior to 4.4.1.0948

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Applied latest upgrade or patch from the vendor:
https://www.qnap.com/zh-tw/security-advisory/nas-201911-25

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-08-04 15.899 Default_action:pass:drop
2020-07-08 15.881