Sales Chat - Click Here

NETBIOS/SMB Vulnerabilities


NETBIOS/SMB Share Vulnerabilities

Advisory Summary

In order to avoid this vulnerability, the system needs to be configured in such as way as to require access restrictions, and to turn off guest access. In addition, the "info" folder, a read only folder that stores convenient documents and applications for NAS management, needs to be disabled, as this is seen as an unsecured share. 

Also update NAS firmware to the latest version:
TS5020 Series FW Ver. 1.63 or later
TS3010, 3020, and 5010 series FW ver. 5.72 or later

Vulnerability ID Vulnerability Overview
CVE-1999-0505 A Windows NT domain user or administrator account has a guessable password.
CVE-1999-0519 A NETBIOS/SMB share password is the default, null, or missing.
CVE-1999-0520 A system-critical NETBIOS/SMB share has inappropriate access control.

 

Affected Supported TeraStations

TS7010/6000/5020/5010/3010/3020

Back to Security Notices

Page Revision History

Date Description
12/21/2022 Initial release
01/22/2024 Firmware update
X