The release deals with OpenSSL and Samba vulnerabilities

Apr 2, 2015 14:32 GMT  ·  By

Buffalo has just released a new firmware update developed for its TS-2RZH and TS-2RZS NAS devices, namely version 2.45, which issues fixes for Samba and OpenSSL 3.0 programming vulnerabilities.

Specifically speaking, the present firmware resolves CVE-2014-3567 and CVE-2014-3568 OpenSSL exposures (also known as POODLE SSL3.0 vulnerabilities), responsible for memory leak and unauthorized access for remote attackers.

In addition to that, Buffalo’s update also resolves CVE-2015-0240, CVE-2014-3493, CVE-2014-0244, and CVE-2014-0178 Samba programming security problems, which also allowed remote authentication and caused memory corruption, daemon crash, or infinite loop and CPU consumption.

When it comes to downloadable files, the producer has provided two downloadable packages: one suitable for Mac OS X 10.4 and later platforms, and the other compatible with Windows 2000, XP, Vista, 7, 8, and 8.1 OSes, as well as with Server 2003, 2008, and 2012 operating systems.

Regardless of which file you save, in order to properly upgrade your NAS, you must extract the archive, close all programs and processes that might interfere with the installation, and run the available setup file only on compatible system configurations.

Afterwards, select the TeraStation unit you want to upgrade, hit “Upgrade,” follow all instructions displayed on-screen, and wait patiently for the process to finish. Once completed, a proper message will be displayed.

That being said, download Buffalo TS-2RZ NAS Series Firmware 2.45, take into account all instructions mentioned above, and enjoy your newly-improved security level.