Rewterz Threat Alert – Emotet Phishing Uses Political Lures
October 8, 2020Rewterz Threat Alert – Ttint – An IoT RAT Exploiting Two 0-Days
October 9, 2020Rewterz Threat Alert – Emotet Phishing Uses Political Lures
October 8, 2020Rewterz Threat Alert – Ttint – An IoT RAT Exploiting Two 0-Days
October 9, 2020Severity
High
Analysis Summary
CVE-2020-2506 | CVE-2020-2507
QNAP has addressed two critical security vulnerabilities in the Helpdesk app that could enable potential attackers to take over unpatched QNAP network-attached storage (NAS) devices. Helpdesk is the built-in app that comes with QNAP’s NAS devices and allows admins to submit help requests to the QNAP support team over the Internet. They’re both improper access control vulnerabilities that “could allow attackers to obtain control of a QNAP device” if successfully exploited.
Impact
Device Takeover
Affected Vendors
QNAP
Affected Products
Helpdesk
Remediation
QNAP has already fixed these issues in Helpdesk 3.0.3 and later versions.
- Log on to QTS as administrator.
- Open the App Center, and then click .
A search box appears. - Type “Helpdesk”, and then press ENTER.
The Helpdesk application appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if you are using the latest version. - Click OK.
The application is updated