TDSCSA00436 Multiple Vulnerabilities in CANVIO Network Storage Products
TDSCSA00436 Multiple Vulnerabilities in CANVIO Network Storage Products
TDSCSA00436 Multiple Vulnerabilities in CANVIO Network Storage Products
CANVIO AeroCast /
HDTU110*KWC1 1.2.8 or earlier
CANVIO AeroCast wireless HDD
■Impact
OSS modules in the Affected Network Storage Products, including samba, have known
vulnerabilities including CVE-2017-7494. The details are shown in the following
“Vulnerability Information for each OSS module list ”.
These vulnerabilities allow remote attackers to cause information leakage / modification,
and to potentially take control of the Affected Network Storage Products.
Via home broadband network Filter traffic related to the Set Wireless product up to AP
vulnerabilities using a firewall mode. *1 *2
device, such as a broadband router.
Via wireless LAN Confirm that there are no wireless 1. Update the latest firmware that
communication devices within your fixed WPA2 vulnerabilities of
local network. Wireless product.
2. Change the default password to a
unique password.
*1: Please be sure to download the user manual and read it carefully prior to setup.
*2: Please be sure to update the latest firmware that addressed WPA2 vulnerabilities.
*3: WWAN means “Wireless Wide Area Network”.
Note: Toshiba Electronic Devices & Storage Corporation terminates the software update for the Affected Network
Storage Product.
Note: Please be sure to apply the appropriate firmware update according to the information provided by the
manufacturer of any devices that are connected to the Affected Network Storage Product.
<Attack route>
<Wireless products>
Different connection modes
・Use the “AP mode” (shown below) to mitigate the impact of these vulnerabilities.
・Please be aware that it is possible that in station and bridge mode vulnerabilities can
occur.
※1
CANVIO AeroCast /
> Download
CANVIO AeroCast wireless HDD
■ Reference
・The latest firmware to address WPA2 vulnerability
・ Common Vulnerability Scoring System SIG
・”Software Update Termination for CANVIO Network Storage Products”
■Contact Information
https://storage.toshiba.com/consumer-hdd/support/contact