- QNAP said it addressed six missing in his hybrid backup -sync tool
- The deficiencies came from rsync, an open source file synchronization tool
- Users are advised to update their HBS right away
QNAP has addressed half a dozen vulnerabilities affecting its hybrid backup sync (HBS) software.
In a security advice, the company noted that the vulnerabilities were discovered in Rsync, an open source file synchronization tool used to transfer and sync files between systems. It supports local and remote controls via SSH and minimizes data transfer with step -by -step updates. Many backup solutions use rsync, including duplicity, bacula, rclone and others.
HBS is a backup backup and disaster recovery solution that supports local, remote and cloud storage services.
Performing arbitrary code
Bugs are tracked as CVE-2024-12084, CVE-2024-12085, CVE-20124-12086, CVE-2024-12087 and CVE-2024-12088 and affects HBS 3 Hybrid Backup Sync 25.1.x. QNAP said they could have been used to run malicious code externally against non -mentioned network attached storage (NAS) final points. Apparently, threat players would only need anonymous reading access to vulnerable servers to exploit the shortcomings.
“When combined, the first two vulnerabilities (heapbuffer overflow and information leakage) provide a client to perform arbitrary code on a device that has a Rsync server running,” said Cert/CC when Rsync 3.4.0 was released . “The client requires only anonymous reading access to the server, such as public mirrors. In addition, attacking can take control of a malicious server and read/write arbitrary files of any connected client.”
To ensure their systems, administrators are advised to update their HBS 3 Hybrid -backup -Sync to Version 25.1.4.952 By logging in to QTS or Quts Hero as Administrator, Open Appcenter and Search for HBS 3 Hybrid -backup -Sync and Click Update button.
According to Bleeping computerThere are currently more than 700,000 IP addresses with exposed Rsync servers, but it is difficult to determine how many can be used.
Via Bleeping computer