SambaCry Vulnerability

Summary

CVE-2017-749

All versions of Samba from 3.5.0 onwards are vulnerable to a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.


Unaffected Quantum Products

The following Quantum products are known to be unaffected by the Samba vulnerability.


Vulnerable Quantum Products

Versions of the following Quantum products are known to be vulnerable to Samba.


Impact

Malicious clients can upload and cause the smbd server to execute a shared library from a writable share.

Solution

Patches to Quantum software and firmware are in progress; please contact your Quantum service representative for the latest status on availability.

References

Contact Information

In US, call 800-284-5101. In Europe, call toll free +800-7826-8888 or direct +49 6131 324 185. You will need your system serial number. For additional contact information, go to http://www.quantum.com/serviceandsupport/get-help/index.aspx#contact-support