Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-3200


The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.


Published

2009-09-21T19:30:00.420

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.9 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

8.5

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware qnap ts-239_pro_turbo_nas 2.1.7_0613 Yes
Hardware qnap ts-239_pro_turbo_nas 3.1.0_0627 Yes
Hardware qnap ts-239_pro_turbo_nas 3.1.1_0815 Yes
Hardware qnap ts-639_pro_turbo_nas 2.1.7_0613 Yes
Hardware qnap ts-639_pro_turbo_nas 3.1.0_0627 Yes
Hardware qnap ts-639_pro_turbo_nas 3.1.1_0815 Yes

References