Security ID : NAS-201805-10
Security Advisory for PHP Vulnerabilities in QTS
Release date : May 10, 2018
CVE identifier : CVE-2016-1283 | CVE-2017-16642 | CVE-2018-5711 | CVE-2018-5712
Affected products: QTS 4.3.3: build 20180126 and earlier versions
QTS 4.3.4: build 20180215 and earlier versions
Severity
Moderate
Status
Resolved
Summary
Several vulnerabilities have been discovered on PHP 5.6.32 and earlier versions. These affect QTS 4.3.3 build 20180126, 4.3.4 build 20180215, and their earlier versions.
If successfully exploited, these vulnerabilities could allow attackers to access sensitive information on the NAS, launch denial-of-service (DoS), or Cross-Site-Scripting (XSS) attacks.
We have already fixed these issues in the following QTS versions
- QTS 4.3.3: build 20180402 and later
- QTS 4.3.4: build 20180315 and later
Recommendation
To fix these vulnerabilities, you must update QTS to the following versions.
- QTS 4.3.3: build 20180402 or later
- QTS 4.3.4: build 20180315 or later
Installing the QTS Update
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
QTS downloads and installs the latest available update.
Revision History: V1.0 (May 10, 2018) - Published