Security ID : QSA-20-07

Zerologon


  • Release date : October 19, 2020

  • CVE identifier : CVE-2020-1472

  • Affected products: Certain QNAP NAS

Severity

Critical

Status

Resolved


Summary

The Zerologon vulnerability has been reported to affect some versions of QTS.

If exploited, this elevation of privilege vulnerability allows remote attackers to bypass security measures via a compromised QTS device on the network. The NAS may be exposed to this vulnerability if users have configured the device as a domain controller in Control Panel > Network & File Services > Win/Mac/NFS > Microsoft Networking.

QNAP has fixed this issue in the following software versions:

  • QTS 4.5.1.1456 build 20201015 and later
  • QTS 4.4.3.1439 build 20200925 and later
  • QTS 4.3.6.1446 Build 20200929 and later
  • QTS 4.3.4.1463 build 20201006 and later
  • QTS 4.3.3.1432 build 20201006 and later

QTS 2.x and QES are not affected by this vulnerability.

Recommendation

To secure your device, we strongly recommend updating QTS and all installed applications to their latest versions to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.

Installing the QTS Update

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.

Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating All Installed Applications

  1. Log on to QTS as administrator.
  2. Go to App Center.
  3. Select My Apps
  4. Beside Install Updates, click All.
    A confirmation message appears.
  5. Click OK.
    QTS updates all your installed applications to their latest versions.

 

Revision History: V1.0 (October 19, 2020) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top