Update your QNAP NAS Server

If you have not done so and got one, please update your QNAP NAS server with A) the latest firmware, and then B) Patch it with QFix 1.0.1, most if not all QNAP servers are vunerable to the GNU Bash Vulnerability. The Qfix 1.0.1 patch addresses the GNU Bash Environment Variable Command Injection Vulnerability (CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-6278, CVE-2014-7186, and CVE-2014-7187), also known as "Shellshock," that can allow attackers to gain remote control over UNIX/Linux-based systems.



QNAP has previously released QTS version 4.1.1 Build 0927 to resolve CVE-2014-6271 and CVE-2014-7169. With Qfix 1.0.1 more vulnerabilities including CVE-2014-6277, CVE-2014-6278, CVE-2014-7186, and CVE-2014-7187 are now resolved. Users are strongly urged to immediately install Qfix 1.0.1 on their Turbo NAS.

Qfix 1.0.1 is now available for Turbo NAS running QTS 4.1.1 from QNAP's official download site for the following models.

QNAP will release a new patch later for the following Turbo NAS models, VioStor NVR models and NMP media players to fix Bash security issues:

The following models are not affected by Bash security vulnerabilities:



Printed from: https://www.guru3d.com/story/update-your-qnap-nas-server/