NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
DNMMM
May 04, 2022Follower
ReadyNAS 524X vulnerability?
I get Nessus reports of one detected vulnerability in a ReadyNAS 524X with firmware 6.10.7.
Vulnerability Desc: | The version of Samba running on the remote host is 4.13.x prior to 4.13.17, 4.14.x prior to 4.14.12, or 4.15.x prior to 4.15.5. It is, therefore, affected by multiple vulnerabilities: - Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution. (CVE-2021-44142) - Information leak via symlinks of existence of files or directories outside of the exported share. (CVE-2021-44141) - Samba AD users with permission to write to an account can impersonate arbitrary services. (CVE-2022-0336) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number. |
Vendor Fix: | Upgrade to Samba version 4.13.17, 4.14.12, or 4.15.5 or later. |
Anyone know if/when this will be fixed?
2 Replies
- JeraldMNETGEAR Employee Retired
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!