openPR Logo
Press release

SoftNAS® Vulnerability Disclosed by Digital Defense, Inc. Researchers

03-22-2019 09:30 AM CET | IT, New Media & Software

Press release from: Digital Defense, Inc.

SoftNAS® Vulnerability Disclosed by Digital Defense, Inc.

San Antonio, TX – March 21, 2019 – Digital Defense, Inc., a leading security technology and services provider, today announced that its Vulnerability Research Team (VRT) discovered a previously undisclosed vulnerability in SoftNAS Cloud® data storage platform. If customers have not followed SoftNAS deployment best practices and have openly exposed SoftNAS StorageCenter® ports directly to the internet, SoftNAS Cloud Enterprise 4.2.0 is vulnerable to an authenticated bypass that could be leveraged to gain access to the webadmin interface without valid user credentials. The vulnerability potentially allows an attacker to create new users or execute arbitrary commands with administrative privileges, compromising both the platform and data. The vulnerability is not present on SoftNAS Cloud versions prior to 4.2 and is fixed in versions 4.2.2 and later.

What You Can Do

Information regarding the security fix can be obtained through the SoftNAS release notes.

Details of the vulnerability can be found on the Digital Defense blog.
Tom DeSot, EVP/Chief Information Officer at Digital Defense, said, “SoftNAS has worked closely with our VRT to ensure a fix is available to organizations utilizing the affected platform. The SoftNAS team was extremely collaborative and diligent in their rapid response to the identification of the issue, resulting in a quick resolution.”

“We’re grateful to have partnered with the Digital Defense VRT to strengthen the security of SoftNAS Cloud. The protection and security of customer data is not only of the utmost importance to the SoftNAS team but is also integral to SoftNAS’ core business mission and vision,” said Rick Braddy, SoftNAS Co-Founder and CTO.

Digital Defense Research Methodology and Practices
The Digital Defense VRT regularly works with organizations in the responsible disclosure of zero-day vulnerabilities. The expertise of the VRT when coupled with the company’s next generation hybrid SaaS Security platform, Frontline.Cloud enables early detection capabilities. When zero-days are discovered and internally validated, the VRT immediately contacts the affected vendor to notify the organization of the new finding(s) and then assists, wherever possible, with the vendor’s remediation actions.

About Digital Defense
Serving clients across numerous industries, Digital Defense’s innovative and leading-edge technology helps organizations safeguard sensitive data and eases the burdens associated with information security. Frontline.Cloud, the original Security SaaS platform, delivers unparalleled accuracy and efficiencies through multiple systems including Frontline Vulnerability Manager (Frontline VM™), Frontline Web Application Scanning (Frontline WAS™), Frontline Active Threat Sweep™ (Frontline ATS™) and Frontline Pen Test™, while SecurED®, the company’s security awareness training, promotes employees’ security-minded behavior. The Digital Defense Frontline suite of products, underpinned by patented technology and complemented with superior service and support, are highly-regarded by industry experts, as illustrated by the company’s designation as 2018 Global Vulnerability Management Customer Value Leadership Award, #10 ranking in Black Book Market Research's list of Compliance & Risk Management Solutions, five-star review in SC Magazine, and inclusion in CRN’s MSP 500.

About SoftNAS
SoftNAS®, Inc. has pioneered cloud data control and management with its SoftNAS Cloud data platform. SoftNAS began six years ago as the global leader in software-defined Cloud NAS and has since matured into an enterprise software company. The SoftNAS Cloud data platform provides customers a unified and integrated way to aggregate, transform, accelerate, protect and store data and to easily create cloud storage solutions that bridge islands of data across SaaS, legacy systems, remote offices, factories, IoT, analytics, AI and machine learning, web services, SQL, NoSQL and the cloud – any kind of data. SoftNAS works with the most popular public, private, hybrid and premises-based virtual cloud operating systems, including Amazon Web Services, Microsoft Azure and VMware vSphere.

Contact Digital Defense at 888-273-1412; visit www.digitaldefense.com, our blog, LinkedIn, or follow @Digital_Defense on Twitter.

To learn more about SoftNAS, follow @SoftNAS on Twitter, LinkedIn, YouTube or the SoftNAS blog.

Digital Defense
9000 Tesoro Drive, Suite 100
San Antonio, TX 78217

Contact Digital Defense at 888-273-1412; visit www.digitaldefense.com, our blog, LinkedIn, or follow @Digital_Defense on Twitter.

Press Contact:

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release SoftNAS® Vulnerability Disclosed by Digital Defense, Inc. Researchers here

News-ID: 1666016 • Views: 589

More Releases from Digital Defense, Inc.

Digital Defense Earns 5-Star Rating in the 2020 CRN® Partner Program Guide
Quick on-boarding, platform ease of use, unparalleled support and revenue building tools give channel providers recipe for success San Antonio, TX, March 30, 2020 - Digital Defense, Inc. today announced that it has received another 5-Star rating from CRN®, a brand of The Channel Company, in its 2020 Partner Program Guide. This annual guide is the definitive listing of the most rewarding partner programs from technology companies that provide products and
Once again, Frontline VM is Designated Best Vulnerability Management Solution Fi …
San Antonio, TX—January 17, 2019—Digital Defense, Inc., a security technology and services provider, today announced that Frontline Vulnerability Manager™ (Frontline VM™) , a Frontline.Cloud system, has again been recognized as a Trust Award finalist in the Best Vulnerability Management Solution category for the 2019 SC Awards. The mission of SC Awards is to honor the achievements of the cybersecurity brands and professionals striving to safeguard businesses, their customers, and critical
NUUO Firmware Vulnerabilities Disclosed by Digital Defense, Inc. Researchers
Digital Defense, Inc., a leading security technology and services provider, today announced that its Vulnerability Research Team (VRT) discovered a previously undisclosed vulnerability in NUUO NVRmini2 Network Video Recorder firmware. NVRmini2 firmware version 3.9.1 and prior is vulnerable to an unauthenticated remote buffer overflow that could potentially be leveraged by an attacker to execute arbitrary code on the system with root privileges. This could allow the attacker to access and/or
Digital Defense Announces Frontline Active Threat Sweep™
Fast, Easy to Deploy, Cost-Effective Alternative to Threat Hunting Platforms San Antonio, TX – November 15, 2018 – Digital Defense, Inc., a leading security technology and services provider, today announced the availability of their next generation Threat Detection technology, Frontline Active Threat Sweep™ (Frontline ATS™), an optional addition to Frontline.Cloud. Frontline ATS – underpinned by Digital Defense’s patented security assessment technology – operationalizes threat intelligence. The solution fills a unique need

All 5 Releases


More Releases for NAS

Consumer NAS and SMB NAS Market - Global Outlook and Forecast 2018-2023 | Arizto …
The global consumer and SMB NAS market size is expected to reach values of approximately $12 billion by 2023, growing at a CAGR of more than 9% 2018–2023, states latest report by Arizton The global consumer and SMB NAS market is driven by the growing demand for efficient, reliable and affordable solutions to store the data. The introduction of enhancing systems that enable remote access to the file, secure storage to
Enterprise NAS
NAS is a storage system that enables file sharing among enterprise users. It is an independent network node in the local area network (LAN) that consists of individual Internet protocol (IP) addresses. File transfer is achieved through an Ethernet connection between users and NAS systems. NAS allows multiple users access to the same file in a network. In an enterprise environment, NAS systems are used for backup, archiving, and disaster recovery
Global Enterprise NAS Market 2015-2019
NAS systems create a shared file based storage between enterprise users. NAS exists as an independent network node on the LAN and comprises individual IP addresses. File transfer is achieved through Ethernet connections between users and NAS. It facilitates simultaneous access to multiple users. NAS systems can be used as backup storage in enterprises for archiving and disaster recovery purposes. NAS systems with server mode can also function as a
Global Enterprise NAS Market 2015-2019
NAS systems create a shared file based storage between enterprise users. NAS exists as an independent network node on the LAN and comprises individual IP addresses. File transfer is achieved through Ethernet connections between users and NAS. It facilitates simultaneous access to multiple users. NAS systems can be used as backup storage in enterprises for archiving and disaster recovery purposes. NAS systems with server mode can also function as a
ASUSTOR Releases Enterprise-Level Rackmount NAS
An optimal storage solution for businesses that features the Intel® Atom™ 2.13 GHz dual core processor and support for VMware, Citrix and Hyper-V virtual environments Taipei, Taiwan, January 29th, 2013 –ASUSTOR Inc., a leading innovator and provider of network storage solutions, today announced the release of four new enterprise-level 1U and 2U rackmount NAS devices. These new devices consist of the four drive bay AS-604RS and AS-604RD models and the nine
ASUSTOR Launches AS 6 Series NAS
New App-based NAS powered by the Intel® Atom™ 2.13 GHz Dual-Core Processor features System Sleep Mode (S3) and local display Taipei, Taiwan, Novemeber 6th, 2012 – ASUSTOR Inc., a leading innovator and provider of network storage solutions, has announced the launch of its all new AS 6 Series Network Attached Storage (NAS). The AS 6 Series NAS devices come in two, four, six and eight-bay models and feature System Sleep Mode