RSS   Vulnerabilities for 'Ts-239 pro turbo nas'   RSS

2009-09-21
 
CVE-2009-3279

CWE-310
 

 
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.

 
 
CVE-2009-3278

CWE-310
 

 
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.

 
 
CVE-2009-3200

CWE-310
 

 
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.

 

 >>> Vendor: QNAP 41 Products
Ts-239 pro turbo nas
Ts-639 pro turbo nas
Surveillance station pro
NAS
Viostor network video recorder
QTS
Photo station
Photo station firmware
Ss-839
Ts-459u
Ts-469u
Ts-ec1679u-rp
Ss-839 firmware
Ts-459u firmware
Ts-469u firmware
Ts-ec1679u-rp firmware
Sinage station
Signage station
Iartist lite
Ts-212p firmware
Qts helpdesk
Music station
Video station
Qsync
Media streaming add-on
Qfinder pro
Q'center
Helpdesk
Q'center virtual appliance
Myqnapcloud
Netbak replicator
Quts hero
Multimedia console
QES
Qutscloud
Roon server
Qulog center
Q\'center
QVR
Qcalagent
Qvr firmware


Copyright 2024, cxsecurity.com

 

Back to Top