QNAP Alert
2693Warning Date
Severity Level
Warning Number
Target Sector
20 April, 2022
● Medium
2022-4692
All
QNAP has released security updates to address several vulnerabilities in the following product:
- QNAP NAS
An attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
- Escalation of privilege
QNAP encourages users apply the following practices:
- Keep the default value "1M" for LimitXMLRequestBody.
- Disable mod_sed. (Note: In QTS, mod_sed is disabled by default in Apache HTTP Server.)
- https://www.qnap.com/en/security-advisory/qsa-22-11