Release date: May 27, 2017
Last updated: May 27, 2017
Bulletin ID: NAS-201705-27
Severity rating: High
CVE identifier: CVE-2017-7494
Affected products: All NAS running QTS
Summary
The Samba team has released an advisory for CVE-2017-7494, a vulnerability that may allow users with write access to upload a shared library to a writeable shared folder and then execute malicious code.
Solution
QNAP is currently working on a fix and will release an update in the coming days. For manually applying a workaround, refer to QNAP Forum ( https://forum.qnap.com/viewtopic.php?f=5&t=132991&p=617561#p617561)
References:
https://www.samba.org/samba/security/CVE-2017-7494.html
https://www.samba.org/samba/history/security.html
https://access.redhat.com/security/cve/CVE-2017-7494
If you have any questions regarding this issue, please contact us at http://helpdesk.qnap.com/.