Lucene search

K
cve[email protected]CVE-2009-3200
HistorySep 21, 2009 - 7:30 p.m.

CVE-2009-3200

2009-09-2119:30:00
CWE-310
web.nvd.nist.gov
26
cve-2009-3200
qnap
ts-239 pro
ts-639 pro
firmware vulnerability
local users
passphrase bypass
hard drive decryption
security
nvd

5.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:C/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.

Affected configurations

NVD
Node
qnapts-239_pro_turbo_nasMatch2.1.7_0613
OR
qnapts-239_pro_turbo_nasMatch3.1.0_0627
OR
qnapts-239_pro_turbo_nasMatch3.1.1_0815
OR
qnapts-639_pro_turbo_nasMatch2.1.7_0613
OR
qnapts-639_pro_turbo_nasMatch3.1.0_0627
OR
qnapts-639_pro_turbo_nasMatch3.1.1_0815

5.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:C/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%