NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

JayLim77's avatar
JayLim77
Aspirant
Apr 24, 2023

Windows Patch for RPC Sealing and Samba for ReadyNAS 4220S

I have a ReadyNAS 4220S running 6.9.3 that is being used for SMB shares.

 

The problem we just found out is that Microsoft is patching RPC authentication to stop RPC Signing and only allow RPC Sealing, CVE-2022-38023. Multiple of our other NAS vendors have been jumping on this as this a huge change.

Also, Samba released this statement, https://www.samba.org/samba/security/CVE-2022-38023.html, and these versions, Samba 4.15.13, 4.16.8 and 4.17.4, and later are patched to fix this issue.

 

I cannot find any updates or release notes that mention being ready for this issue or not. Is this issue not affecting ReadyNAS or is it still being worked to resolve this issue?

 

Any help would be greatly appreciated.

9 Replies

  • The patch from Microsoft will be applied next month and was hoping someone might know if ReadyNAS 4220S is or will be patched and is or is not vulnerable to having issues with the change by Microsoft.

    • AnkitGH's avatar
      AnkitGH
      NETGEAR Moderator

      Hello JayLim77 

       

      And welcome to the NETGEAR Community! 🙂

       

      Yes, Microsoft have released its initial security deployment it is in initial deployment phase and it is released in Nov 8 2022.

      And as you mentioned the patch will be enforced soon.

       

      And ReadyNAS updated firmware version is 6.10.8 and it will not probably update the version in near future. 

      Please keep the device in the updated firmware to avoid the vulnerabilities.

       

      Probably it is will not affect the NAS in which the change by the Microsoft.

       

      If your issue is resolved please close the thread by clicking "Accept as solution".


      Have a lovely day,
      AnkitGH
      Netgear Team

      • Sandshark's avatar
        Sandshark
        Sensei

        AnkitGH wrote:

        Hello JayLim77 

         

        Probably it is will not affect the NAS in which the change by the Microsoft.

         

        Your best answer is probably it won't affect the NAS?  That just won't do.  From what I have read, it very much will affect anyone using AD integration to access the NAS, which I assume the original poster is doing. 

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More