Vulnerability in QNAP TS-239 Pro and TS-639 Pro Affects Firmware Security
CVE-2009-3279

Currently unrated

Key Information:

Vendor
Qnap
Vendor
CVE Published:
21 September 2009

Summary

The QNAP TS-239 Pro and TS-639 Pro devices with specified firmware versions utilize AES-256 encryption in plain CBC mode to create LUKS partitions. This implementation flaw enables local users to potentially extract sensitive information through a watermark attack, compromising data integrity and confidentiality.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.