=====================================================================

                                 CERT-Renater

                       Note d'Information No. 2023/VULN456

_____________________________________________________________________

DATE                : 06/11/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running QTS versions 5.1.x, 4.3.6,
                               4.3.4, 4.3.3, 4.2.x;
                    Multimedia Console versions 2.1.x, 1.4.x;
                    Media Streaming add-on versions 500.1.x, 500.0.x.

=====================================================================
https://www.qnap.com/en/security-advisory/qsa-23-35
_____________________________________________________________________

Security ID : QSA-23-35
Vulnerability in QTS, Multimedia Console, and Media Streaming add-on

     Release date : November 4, 2023

     CVE identifier : CVE-2023-23369

     Affected products: QTS 5.1.x, 4.3.6, 4.3.4, 4.3.3, 4.2.x;
Multimedia Console 2.1.x, 1.4.x; Media Streaming add-on 500.1.x,
500.0.x


Severity
Critical

Status
Resolved


Summary

An OS command injection vulnerability has been reported to affect
several QNAP operating system and application versions. If exploited,
the vulnerability could allow remote attackers to execute commands
via a network.

We have already fixed the vulnerability in the following versions:

Affected Product     Fixed Version
QTS 5.1.x                    QTS 5.1.0.2399 build 20230515 and later
QTS 4.3.6                    QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.4                    QTS 4.3.4.2451 build 20230621 and later
QTS 4.3.3                    QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.x                    QTS 4.2.6 build 20230621 and later
Multimedia Console 2.1.x     Multimedia Console 2.1.2 (2023/05/04)
                                            and later
Multimedia Console 1.4.x     Multimedia Console 1.4.8 (2023/05/05)
                                             and later
Media Streaming add-on 500.1.x 	Media Streaming add-on 500.1.1.2
                                       (2023/06/12) and later
Media Streaming add-on 500.0.x 	Media Streaming add-on 500.0.0.11
                                       (2023/06/16) and later


Recommendation

To secure your device, we recommend regularly updating your system
and applications to the latest version to benefit from vulnerability
fixes. You can check the product support status to see the latest
updates available to your NAS model.


Updating QTS

     Log in to QTS as an administrator.
     Go to Control Panel > System > Firmware Update.
     Under Live Update, click Check for Update.
     The system downloads and installs the latest available update.

Tip: You can also download the update from the QNAP website. Go to
Support > Download Center and then perform a manual update for your
specific device.


Updating Multimedia Console

     Log on to QTS as an administrator.
     Open the App Center and then click .
     A search box appears.
     Type "Multimedia Console" and then press ENTER.
     Multimedia Console appears in the search results.
     Click Update.
     A confirmation message appears.
     Note: The Update button is not available if your version
is already up to date.
     Click OK.
     The application is updated.

Updating Media Streaming add-on

     Log on to QTS as an administrator.
     Open the App Center and then click .
     A search box appears.
     Type "Media Streaming add-on" and then press ENTER.
     Media Streaming add-on appears in the search results.
     Click Update.
     A confirmation message appears.
     Note: The Update button is not available if your version
is already up to date.
     Click OK.
     The application is updated.


Attachment

     CVE-2023-23369.json


Acknowledgements: Eqqie


Revision History:
V1.0 (November 4, 2023) - Published



=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
