¡¾Â©¶´Í¨¸æ¡¿QNAP QTS & QuTS Hero & QuTScloudÃüÁî×¢Èë©¶´£¨CVE-2023-23368£©

Ðû²¼Ê±¼ä 2023-11-07


Ò»¡¢Â©¶´¸ÅÊö

CVE   ID

CVE-2023-23368

·¢ÏÖʱ¼ä

2023-11-07

Àà    ÐÍ

ÃüÁî×¢Èë

µÈ    ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÅÓ´ó¶È

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 

QNAP Systems, Inc.£¨ÍþÁªÍ¨¿Æ¼¼£©Ö÷ÒªÉú²úÓÃÓÚÎļþ¹²Ïí¡¢ÐéÄ⻯¡¢´æ´¢¹ÜÀíºÍ¼à¿ØÓ¦ÓõÄÍøÂ總¼Ó´æ´¢£¨NAS£©É豸¡£

11ÔÂ7ÈÕ£¬¶«É­Æ½Ì¨VSRC¼à²âµ½QNAPÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä¶à¸öQNAPϵͳÖеÄÒ»¸öÃüÁî×¢Èë©¶´£¨CVE-2023-23368£©£¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£¸Ã©¶´Ó°ÏìÁËQTS ¡¢QuTS Hero ºÍQuTScloudµÄ¶à¸ö°æ±¾£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÔ¶³ÌÖ´ÐÐÃüÁî¡£

´ËÍ⣬QNAP»¹ÐÞ¸´ÁËQNAPϵͳºÍÓ¦Ó÷¨Ê½ÖеÄÁíÒ»¸öÃüÁî×¢Èë©¶´£¨CVE-2023-23369£¬CVSSv3ÆÀ·ÖΪ9.0£©£¬¸Ã©¶´Ó°ÏìÁËQTS¡¢Multimedia Console¡¢Media Streaming add-onµÄ¶à¸ö°æ±¾£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÀûÓøÃ©¶´ÔÚ¸ßÅÓ´ó¶È¹¥»÷ÖÐÔ¶³ÌÖ´ÐÐÃüÁî¡£


¶þ¡¢Ó°Ï췶Χ

CVE-2023-23368

QTS 5.0.x < QTS 5.0.1.2376 build 20230421

QTS 4.5.x < QTS 4.5.4.2374 build 20230416

QuTS hero h5.0.x < QuTS hero h5.0.1.2376 build 20230421

QuTS hero h4.5.x < QuTS hero h4.5.4.2374 build 20230417

QuTScloud c5.0.x < QuTScloud c5.0.1.2374

CVE-2023-23369

QTS 5.1.x < QTS 5.1.0.2399 build 20230515

QTS 4.3.6 < QTS 4.3.6.2441 build 20230621

QTS 4.3.4 < QTS 4.3.4.2451 build 20230621

QTS 4.3.3 < QTS 4.3.3.2420 build 20230621

QTS 4.2.x < QTS 4.2.6 build 20230621

Multimedia Console 2.1.x < Multimedia Console 2.1.2 (2023/05/04)

Multimedia Console 1.4.x < Multimedia Console 1.4.8 (2023/05/05)

Media Streaming add-on 500.1.x < Media Streaming add-on 500.1.1.2 (2023/06/12)

Media Streaming add-on 500.0.x  < Media Streaming add-on 500.0.0.11 (2023/06/16)

 

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ¸Ã©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º

CVE-2023-23368

QTS 5.0.x >= QTS 5.0.1.2376 build 20230421

QTS 4.5.x >= QTS 4.5.4.2374 build 20230416

QuTS hero h5.0.x >= QuTS hero h5.0.1.2376 build 20230421

QuTS hero h4.5.x >= QuTS hero h4.5.4.2374 build 20230417

QuTScloud c5.0.x >= QuTScloud c5.0.1.2374

CVE-2023-23369

QTS 5.1.x >= QTS 5.1.0.2399 build 20230515

QTS 4.3.6 >= QTS 4.3.6.2441 build 20230621

QTS 4.3.4 >= QTS 4.3.4.2451 build 20230621

QTS 4.3.3 >= QTS 4.3.3.2420 build 20230621

QTS 4.2.x >= QTS 4.2.6 build 20230621

Multimedia Console 2.1.x >= Multimedia Console 2.1.2 (2023/05/04)

Multimedia Console 1.4.x >= Multimedia Console 1.4.8 (2023/05/05)

Media Streaming add-on 500.1.x  >= Media Streaming add-on 500.1.1.2 (2023/06/12)

Media Streaming add-on 500.0.x  >= Media Streaming add-on 500.0.0.11 (2023/06/16)

ÏÂÔØÁ´½Ó£º

 https://www.qnap.com/en/download

×¢£º¸üÐÂQTS ¡¢QuTS hero»ò QuTScloud²½ÖèÈçÏ£º

1.    ÒÔ¹ÜÀíÔ±Éí·ÝµÇ¼QTS ¡¢QuTS hero»ò QuTScloud £»

2.    ½øÈ롾¿ØÖÆÃæ°å¡¿>¡¾ÏµÍ³¡¿>¡¾¹Ì¼þ¸üС¿ £»

3.    ÔÚ¡¾ÊµÊ±¸üС¿Ï£¬µ¥»÷¡¾¼ì²é¸üС¿ £»

ϵͳÏÂÔØ²¢°²×°×îеĿÉÓøüС£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉýÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://www.qnap.com/en-uk/security-advisory/qsa-23-31

https://www.qnap.com/en-uk/security-advisory/qsa-23-35

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-11-07

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png