QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models
2021-08-09T18:15:07.120
2024-11-21T01:58:56.353
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | qnap | viocard-30_firmware | 2312_2.1.0 | Yes |
Hardware | qnap | viocard-30 | - | No |
Operating System | qnap | viocard-100_firmware | - | Yes |
Hardware | qnap | viocard-100 | - | No |
Operating System | qnap | viocard-300_firmware | rc_b3722 | Yes |
Operating System | qnap | viocard-300_firmware | rs_b4631 | Yes |
Hardware | qnap | viocard-300 | - | No |
Operating System | qnap | viogate-340a_firmware | - | Yes |
Hardware | qnap | viogate-340a | - | No |
Operating System | qnap | viogate-340_firmware | 2308_2.1.0 | Yes |
Hardware | qnap | viogate-340 | - | No |