2025年9月1日星期一

QNAP NAS 多個漏洞

QNAP NAS 多個漏洞

發佈日期: 2025年09月01日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 QNAP NAS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及資料篡改。


QNAP NAS Multiple Vulnerabilities

QNAP NAS Multiple Vulnerabilities

Release Date: 1 Sep 2025

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • QTS 5.2.x
  • QuTS hero h5.2.x

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞

發佈日期: 2025年09月01日

風險: 中度風險

類型: 操作系統 - LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、遠端執行程式碼、阻斷服務狀況及資料篡改。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 篡改
  • 資料洩露

受影響之系統或技術

  • Basesystem Module 15-SP6
  • Basesystem Module 15-SP7
  • Development Tools Module 15-SP6
  • Development Tools Module 15-SP7
  • Legacy Module 15-SP6
  • Legacy Module 15-SP7
  • openSUSE Leap 15.6
  • Public Cloud Module 15-SP6
  • Public Cloud Module 15-SP7
  • SUSE Linux Enterprise Desktop 15 SP6
  • SUSE Linux Enterprise Desktop 15 SP7
  • SUSE Linux Enterprise High Availability Extension 15 SP6
  • SUSE Linux Enterprise High Availability Extension 15 SP7
  • SUSE Linux Enterprise Live Patching 15-SP6
  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Real Time 15 SP6
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP6
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Linux Enterprise Workstation Extension 15 SP6
  • SUSE Linux Enterprise Workstation Extension 15 SP7
  • SUSE Linux Micro 6.0
  • SUSE Linux Micro 6.1
  • SUSE Linux Micro Extras 6.0
  • SUSE Real Time Module 15-SP6

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 1 Sep 2025

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, denial of service condition and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Information Disclosure

System / Technologies affected

  • Basesystem Module 15-SP6
  • Basesystem Module 15-SP7
  • Development Tools Module 15-SP6
  • Development Tools Module 15-SP7
  • Legacy Module 15-SP6
  • Legacy Module 15-SP7
  • openSUSE Leap 15.6
  • Public Cloud Module 15-SP6
  • Public Cloud Module 15-SP7
  • SUSE Linux Enterprise Desktop 15 SP6
  • SUSE Linux Enterprise Desktop 15 SP7
  • SUSE Linux Enterprise High Availability Extension 15 SP6
  • SUSE Linux Enterprise High Availability Extension 15 SP7
  • SUSE Linux Enterprise Live Patching 15-SP6
  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Real Time 15 SP6
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP6
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Linux Enterprise Workstation Extension 15 SP6
  • SUSE Linux Enterprise Workstation Extension 15 SP7
  • SUSE Linux Micro 6.0
  • SUSE Linux Micro 6.1
  • SUSE Linux Micro Extras 6.0
  • SUSE Real Time Module 15-SP6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

QNAP NAS 多個漏洞

QNAP NAS 多個漏洞 發佈日期: 2025年09月01日 風險: 中度風險 類型: 伺服器 - 其他伺服器 於 QNAP NAS 發現多個...