First published: Mon Sep 21 2009(Updated: )
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Ts-239 Pro Turbo Nas | =3.1.0_0627 | |
Qnap Ts-639 Pro Turbo Nas | =2.1.7_0613 | |
Qnap Ts-239 Pro Turbo Nas | =3.1.1_0815 | |
Qnap Ts-639 Pro Turbo Nas | =3.1.0_0627 | |
Qnap Ts-239 Pro Turbo Nas | =2.1.7_0613 | |
Qnap Ts-639 Pro Turbo Nas | =3.1.1_0815 | |
All of | ||
Any of | ||
Qnap Ts-239 Pro Firmware | =2.1.7-build0613 | |
Qnap Ts-239 Pro Firmware | =3.1.0-build0627 | |
Qnap Ts-239 Pro Firmware | =3.1.1-build0815 | |
QNAP TS-239 Pro | ||
All of | ||
Any of | ||
Qnap Ts-639 Pro Firmware | =2.1.7-build0613 | |
Qnap Ts-639 Pro Firmware | =3.1.0-build0627 | |
Qnap Ts-639 Pro Firmware | =3.1.1-build0815 | |
Qnap Ts-639 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.