Buffalo Forums

Products => Storage => Topic started by: Eastmarch on June 08, 2017, 11:14:41 AM

Title: UPDATED : Investigation of CVE-2017-7494 (SambaCry) On Buffalo NAS and Routers
Post by: Eastmarch on June 08, 2017, 11:14:41 AM
Possible issue :

Description from https://www.samba.org/samba/security/CVE-2017-7494.html

All versions of Samba from 3.5.0 onwards are vulnerable to a remote
code execution vulnerability, allowing a malicious client to upload a
shared library to a writable share, and then cause the server to load
and execute it.

Affected Products :

TERASTATION:
TS5010 - Resolved by firmware 3.20 released 6/19/2017 (Only Windows updater available at this time)
TS3010 - Resolved by firmware 3.20 released 6/19/2017 (Only Windows updater available at this time)
TS7000 - Resolved by firmware 2.61 released 6/20/2017
TS5000 - Resolved by firmware 3.52 released 6/27/2017
TS5200DS
TS3000 - Resolved by firmware 1.82 released 6/20/2017
TS1000 - Resolved by firmware 1.60 released 7/10/2017
TS-X - Resolved by firmware 1.71 released 7/3/2017
TS-V - Resolved by firmware 1.30 released 7/12/2017

LINKSTATION:
LS400 - Resolved by firmware 1.83 released 6/27/2017
LS200 - Resolved by firmware 1.66 released 6/27/2017
LS-X - Resolved by firmware 1.73 released 7/3/2017
LS-V - Resolved by firmware 1.73 released 7/3/2017

Recommendation :

We will release firmware that will resolve this issue as soon as possible. As a precaution in the meantime, be certain that write access to Samba shares are granted only to trusted users.
Browser ID: smf (is_webkit)
Templates: 1: Printpage (default).
Sub templates: 4: init, print_above, main, print_below.
Language files: 1: index+Modifications.english (default).
Style sheets: 0: .
Hooks called: 45 (show)
Files included: 27 - 1055KB. (show)
Memory used: 734KB.
Tokens: post-login.
Queries used: 10.

[Show Queries]