Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.144825
Category:General
Title:QNAP QTS Zerologon Vulnerability
Summary:QNAP QTS is prone to the Zerologon vulnerability.
Description:Summary:
QNAP QTS is prone to the Zerologon vulnerability.

Vulnerability Insight:
If exploited, this elevation of privilege vulnerability allows remote
attackers to bypass security measures via a compromised QTS device on the network. The NAS may be exposed to
this vulnerability if users have configured the device as a domain controller in Control Panel >
Network & File Services > Win/Mac/NFS > Microsoft Networking.

Affected Software/OS:
QNAP QTS versions 4.3.3, 4.3.4, 4.3.6, 4.4.3 and 4.5.1.

Solution:
Update to version 4.3.3.1432 build 20201006, 4.3.4.1463 build 20201006,
4.3.6.1446 Build 20200929, 4.4.3.1439 build 20200925, 4.5.1.1456 build 20201015 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-1472
CERT/CC vulnerability note: VU#490028
https://www.kb.cert.org/vuls/id/490028
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TAPQQZZAT4TG3XVRTAFV2Y3S7OAHFBUP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ST6X3A2XXYMGD4INR26DQ4FP4QSM753B/
http://packetstormsecurity.com/files/159190/Zerologon-Proof-Of-Concept.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
http://www.openwall.com/lists/oss-security/2020/09/17/2
SuSE Security Announcement: openSUSE-SU-2020:1513 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00080.html
SuSE Security Announcement: openSUSE-SU-2020:1526 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00086.html
https://usn.ubuntu.com/4510-1/
https://usn.ubuntu.com/4510-2/
https://usn.ubuntu.com/4559-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.