Go To Content
:::

Tainan Branch, Administrative Enforcement Agency, Ministry of Justice:Back to homepage

:::

QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug

  • Publication Date :
  • Last updated:2022-06-21
  • View count:80

QNAP is warning clients that a recently disclosed vulnerability affects most of its NAS devices, with no mitigation available while the vendor readies a patch.

Customers of Taiwan-based QNAP Systems are in a bit of limbo, waiting until the company releases a patch for an OpenSSL bug that the company has warned affects most of its network-attached storage (NAS) devices. The vulnerability can trigger an infinite loop that creates a denial-of-service (DoS) scenario.

Though the bug – tracked as CVE-2022-0778 and rated 7.5 (high severity) on the CVSS severity-rating scale – has been patched by OpenSSL, QNAP hasn’t gotten around to applying a fix yet for its NAS devices affected by the vulnerability. The company is telling customers that “there is no mitigation available” and they “must check back and install security updates as soon as they become available.”

“QNAP is thoroughly investigating the case,” the company said. “We will release security updates and provide further information as soon as possible.”

Go Top