CVE-2009-3278: Weak RNG
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3278?
The severity of CVE-2009-3278 is classified as medium, as it allows local users to potentially recover sensitive data.
How is CVE-2009-3278 exploited?
CVE-2009-3278 can be exploited through a brute-force attack to determine a certain recovery key due to weak random number generation.
Which QNAP devices are affected by CVE-2009-3278?
CVE-2009-3278 affects QNAP TS-239 Pro and TS-639 Pro with specific firmware versions including 2.1.7, 3.1.0, and 3.1.1.
How do I fix CVE-2009-3278?
To fix CVE-2009-3278, update your QNAP firmware to the latest version provided by QNAP that addresses this vulnerability.
What are the consequences of not addressing CVE-2009-3278?
Not addressing CVE-2009-3278 may lead to unauthorized access to sensitive recovery keys by local users.