Vulnerability Name: | CVE-2009-3279 (CCN-53577) | ||||||||
Assigned: | 2009-09-18 | ||||||||
Published: | 2009-09-18 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:U/RC:UR)
1.5 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3279 Source: CCN Type: SA36793 QNAP Devices Hard Disk Encryption Security Bypass Source: SECUNIA Type: UNKNOWN 36793 Source: CCN Type: Baseline Security Consulting Web site Crypto backdoor in Qnap storage devices Source: MISC Type: Exploit http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt Source: CCN Type: OSVDB ID: 58346 QNAP LUKS Partition AES-256 Cipher Plain CBC Mode Watermark Attack Information Disclosure Source: CCN Type: QNAP Systems Web site QNAP Storage Products Source: BUGTRAQ Type: UNKNOWN 20090918 Advisory: Crypto backdoor in Qnap storage devices (CVE-2009-3200) Source: XF Type: UNKNOWN ts239-ts639-aes256-weak-security(53577) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |