Security News > 2022 > April > QNAP Advises Users to Update NAS Firmware to Patch Apache HTTP Vulnerabilities
Network-attached storage appliance maker QNAP on Thursday said it's investigating its lineup for potential impact arising from two security vulnerabilities that were addressed in the Apache HTTP server last month.
The critical flaws, tracked as CVE-2022-22721 and CVE-2022-23943, are rated 9.8 for severity on the CVSS scoring system and impact Apache HTTP Server versions 2.4.52 and earlier -.
CVE-2022-22721 - Possible buffer overflow with very large or unlimited LimitXMLRequestBody.
CVE-2022-23943 - Out-of-bounds Write vulnerability in mod sed of Apache HTTP Server.
"While CVE-2022-22719 and CVE-2022-22720 do not affect QNAP products, CVE-2022-22721 affects 32-bit QNAP NAS models, and CVE-2022-23943 affects users who have enabled mod sed in Apache HTTP Server on their QNAP device," the Taiwanese company said in an alert published this week.
In the absence of readily available security updates, QNAP has offered workarounds, including "Keeping the default value '1M' for LimitXMLRequestBody" and disabling mod sed, adding that the mod sed feature is disabled by default in Apache HTTP Server on NAS devices running the QTS operating system.
News URL
https://thehackernews.com/2022/04/qnap-advises-users-to-update-nas.html
Related news
- Patch Tuesday: Internet Explorer Vulnerabilities Still Pose a Problem (source)
- QNAP fixes NAS backup software zero-day exploited at Pwn2Own (source)
- Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices (source)
- Patch Tuesday: Four Critical Vulnerabilities Paved Over (source)
- Apple Releases Urgent Updates to Patch Actively Exploited Zero-Day Vulnerabilities (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-14 | CVE-2022-23943 | Out-of-bounds Write vulnerability in multiple products Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. | 9.8 |
2022-03-14 | CVE-2022-22721 | Integer Overflow or Wraparound vulnerability in multiple products If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. | 9.1 |
2022-03-14 | CVE-2022-22720 | HTTP Request Smuggling vulnerability in multiple products Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | 9.8 |
2022-03-14 | CVE-2022-22719 | Improper Initialization vulnerability in multiple products A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. | 7.5 |