QNAP Newsroom

Keep up to date with the latest QNAP news, awards and connect with our team

QNAP Releases System Updates to Fix Heartbleed OpenSSL Vulnerability

Taipei, Taiwan, April 18, 2014 – QNAP® Systems Inc. today announced firmware updates for Turbo NAS systems with vulnerability to the OpenSSL Heartbleed bug (CVE-2014-0160). The operating systems vulnerable to Heartbleed are QTS versions 4.0 and 4.1. Versions 3.8 and earlier use a different version of OpenSSL and are not affected by the OpenSSL Heartbleed bug.

As described on the Common Vulnerabilities and Exposures website, the OpenSSL 1.0.1 TLS and DTLS implementation, before 1.0.1g, does not properly process Heartbeat Extension packets which allow remote attackers to obtain sensitive information by reading private keys (aka the Heartbleed bug).

“We strongly urge users of vulnerable Turbo NAS systems to update their firmware,” said Jason Hsu, Product Manager of QNAP. “Users are also recommended to contact their SSL providers to regenerate their SSL CSR/keys for server protection.”

To obtain the system updates (QTS 4.0.7 and QTS 4.1.0 RC2) with recompiled OpenSSL, please download from www.qnap.com/i/en/product_x_down/ or have your Turbo NAS perform a live update via the QTS control panel.

For more information, please contact us at http://helpdesk.qnap.com/

 

About QNAP

QNAP delivers integrated technology solutions through software innovation, hardware craftsmanship, and in-house manufacturing. With strengths in storage, networking, and smart video surveillance, QNAP also integrates cloud services to enhance data safety, intelligence, and workflow efficiency. We envision the NAS as a core platform unifying high availability, cybersecurity, edge AI, IT/OT resilience, and cloud management—empowering organizations across industries to stay competitive in a rapidly evolving digital world.

Media inquiries

marketing@qnap.com

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top