Security ID : QSA-22-12

Multiple Vulnerabilities in Netatalk


  • Release date : April 25, 2022

  • CVE identifier : CVE-2021-31439 | CVE-2022-23121 | CVE-2022-23123 | CVE-2022-23122 | CVE-2022-23125 | CVE-2022-23124 | CVE-2022-0194

  • Affected products: Certain QNAP NAS

Severity

Important

Status

Resolved


Summary

Upon the latest release of Netatalk 3.1.13, the Netatalk development team disclosed multiple fixed vulnerabilities affecting earlier versions of the software: CVE-2021-31439, CVE-2022-23121, CVE-2022-23123, CVE-2022-23122, CVE-2022-23125, CVE-2022-23124, and CVE-2022-0194.

These vulnerabilities currently affect the following QNAP operating system versions:

  • QTS 5.0.x
  • QTS 4.5.4
  • QTS 4.3.6
  • QTS 4.3.3
  • QTS 4.2.6
  • QuTS hero h5.0.x
  • QuTS hero h4.5.4
  • QuTScloud c5.0.x

We have already fixed the vulnerabilities in the following versions of QTS:

  • QTS 5.0.1.2034 Build 20220515 and later
  • QTS 5.0.0.2055 build 20220531 and later
  • QTS 4.5.4.2012 build 20220419 and later
  • QTS 4.3.6.2050 build 20220526 and later
  • QTS 4.3.4.2107 build 20220712 and later
  • QTS 4.3.3.2057 build 20220623 and later
  • QTS 4.2.6 build 20220623 and later
  • QuTS hero h5.0.0.2022 build 20220428 and later
  • QuTS hero h4.5.4.2052 build 20220530 and later
  • QuTScloud c5.0.1.2044 and later

QNAP is thoroughly investigating the case. We will release security updates for all affected QNAP operating system versions and provide further information as soon as possible.

Recommendation

To mitigate these vulnerabilities, disable AFP. We recommend users to check back and install security updates as soon as they become available.

Updating QTS, QuTS hero, or QuTScloud

  1. Log on to QTS, QuTS hero, or QuTScloud as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS, QuTS hero, or QuTScloud downloads and installs the latest available update.

Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Revision History:
V1.0 (April 25, 2022) - Published
V1.1 (May 11, 2022) - Security update available for QuTS hero h5.0.0
V1.2 (May 20, 2022) - Security update available for QTS 5.0.1 Public Beta
V1.3 (June, 10, 2022) - Security update available for QTS 5.0.0
V1.4 (June, 28, 2022) - Security update available for QTS 4.3.6, QuTS hero h4.5.4 and QuTScloud c5.0.1
V1.5 (July, 12, 2022) - Security update available for QTS 4.3.3
V1.6 (July, 14, 2022) - Security update available for QTS 4.2.6
V2.0 (July, 26, 2022) - Security update available for QTS 4.3.4
V2.1 (June, 8, 2023) - Minor content correction

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top