{"id":63315,"date":"2022-03-31T02:26:07","date_gmt":"2022-03-31T04:26:07","guid":{"rendered":"https:\/\/teknomers.com\/fr\/qnap-met-en-garde-contre-la-vulnerabilite-openssl-infinite-loop-affectant-les-peripheriques-nas\/"},"modified":"2022-03-31T02:26:19","modified_gmt":"2022-03-31T04:26:19","slug":"qnap-met-en-garde-contre-la-vulnerabilite-openssl-infinite-loop-affectant-les-peripheriques-nas","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/qnap-met-en-garde-contre-la-vulnerabilite-openssl-infinite-loop-affectant-les-peripheriques-nas\/","title":{"rendered":"QNAP met en garde contre la vuln\u00e9rabilit\u00e9 OpenSSL Infinite Loop affectant les p\u00e9riph\u00e9riques NAS"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La soci\u00e9t\u00e9 ta\u00efwanaise QNAP a r\u00e9v\u00e9l\u00e9 cette semaine qu&#8217;un certain nombre de ses appliances de stockage en r\u00e9seau (NAS) sont affect\u00e9es par un bogue r\u00e9cemment divulgu\u00e9 dans la biblioth\u00e8que cryptographique open source OpenSSL.<\/p>\n<p>&#8220;Une vuln\u00e9rabilit\u00e9 de boucle infinie dans OpenSSL a \u00e9t\u00e9 signal\u00e9e comme affectant certains NAS QNAP&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/www.qnap.com\/en-in\/security-advisory\/qsa-22-06\" target=\"_blank\">mentionn\u00e9<\/a> dans un avis publi\u00e9 le 29 mars 2022. &#8220;Si elle est exploit\u00e9e, la vuln\u00e9rabilit\u00e9 permet aux attaquants de mener des attaques par d\u00e9ni de service.&#8221;<\/p>\n<p>Suivi en tant que CVE-2022-0778 (score CVSS\u00a0: 7,5), le probl\u00e8me concerne un bogue qui survient lors de l&#8217;analyse des certificats de s\u00e9curit\u00e9 pour d\u00e9clencher une condition de d\u00e9ni de service et planter \u00e0 distance des appareils non corrig\u00e9s.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/TrickBot-Gang-est-susceptible-de-modifier-ses-operations-pour-passer.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>QNAP, qui enqu\u00eate actuellement sur sa gamme, a d\u00e9clar\u00e9 que cela affectait les versions de syst\u00e8me d&#8217;exploitation suivantes &#8211;<\/p>\n<ul>\n<li>QTS 5.0.x et versions ult\u00e9rieures<\/li>\n<li>QTS 4.5.4 et versions ult\u00e9rieures<\/li>\n<li>QTS 4.3.6 et versions ult\u00e9rieures<\/li>\n<li>QTS 4.3.4 et versions ult\u00e9rieures<\/li>\n<li>QTS 4.3.3 et versions ult\u00e9rieures<\/li>\n<li>QTS 4.2.6 et versions ult\u00e9rieures<\/li>\n<li>QuTS hero h5.0.x et versions ult\u00e9rieures<\/li>\n<li>QuTS hero h4.5.4 et versions ult\u00e9rieures, et<\/li>\n<li>QuTScloud c5.0.x<\/li>\n<\/ul>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/thehackernews.com\/new-images\/img\/a\/AVvXsEjaTgAp88VhU4VFlJ_PU8VQX15i_tz3jK4y0rAjaZ920ivKIKwWzBoxVCYtFnVvihCwzEx-6YUNHTO_TveW-zxlJMumYjrnkYbfht6Q6xP-BITctZ1yZAtrMceEcvDaTkybWCLGZm3GvobVHOljShT4hAzHzLosChAtVt7TzWTInUk3HS-pJ1ypa0srkw=s728-e100\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>\u00c0 ce jour, rien ne prouve que la vuln\u00e9rabilit\u00e9 ait \u00e9t\u00e9 exploit\u00e9e \u00e0 l&#8217;\u00e9tat sauvage.  Bien que l&#8217;\u00e9quipe italienne de r\u00e9ponse aux incidents de s\u00e9curit\u00e9 informatique (CSIRT) <a rel=\"nofollow noopener\" href=\"https:\/\/www.csirt.gov.it\/contenuti\/rilevata-vulnerabilita-in-openssl-al02-220316-csirt-ita\" target=\"_blank\">a publi\u00e9 un avis<\/a> au contraire, le 16 mars, l&#8217;agence a pr\u00e9cis\u00e9 \u00e0 The Hacker News qu&#8217;elle avait &#8220;mis \u00e0 jour l&#8217;alerte avec un errata corrige&#8221;.<\/p>\n<p>L&#8217;avis intervient une semaine apr\u00e8s que QNAP a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour QuTS hero (version h5.0.0.1949 build 20220215 et versions ult\u00e9rieures) pour r\u00e9soudre la faille d&#8217;escalade des privil\u00e8ges locaux &#8220;Dirty Pipe&#8221; affectant ses appareils.  Des correctifs pour les syst\u00e8mes d&#8217;exploitation QTS et QuTScloud devraient \u00eatre publi\u00e9s prochainement.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/qnap-warns-of-openssl-infinite-loop.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La soci\u00e9t\u00e9 ta\u00efwanaise QNAP a r\u00e9v\u00e9l\u00e9 cette semaine qu&#8217;un certain nombre de ses appliances de stockage en r\u00e9seau (NAS) sont affect\u00e9es par un bogue r\u00e9cemment divulgu\u00e9 dans la biblioth\u00e8que cryptographique open source OpenSSL. &#8220;Une vuln\u00e9rabilit\u00e9 de boucle infinie dans OpenSSL a \u00e9t\u00e9 signal\u00e9e comme affectant certains NAS QNAP&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. mentionn\u00e9 dans un [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":63316,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[34911,4168,841,4158,4165,4161,525,39899,4157,4159,4171,4170,65,4167,39900,4955,4160,5266,4163,4162,28969,5265,27510,4172,4169,4166,3667,4164],"class_list":["post-63315","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affectant","tag-comment-pirater","tag-contre","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-garde","tag-infinite","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-loop","tag-met","tag-mises-a-jour-de-la-cybersecurite","tag-nas","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-openssl","tag-peripheriques","tag-qnap","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/63315","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=63315"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/63315\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/63316"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=63315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=63315"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=63315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}