CVE-2009-3279: Medium severity qnap nas vulnerability
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3279?
CVE-2009-3279 is considered to have a medium severity due to the potential exposure of sensitive information.
How do I fix CVE-2009-3279?
To address CVE-2009-3279, upgrade the firmware of the QNAP TS-239 Pro and TS-639 Pro to the latest version provided by QNAP.
Who is affected by CVE-2009-3279?
CVE-2009-3279 affects users of the QNAP TS-239 Pro and TS-639 Pro with specific firmware versions 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815.
What specifically causes the vulnerability in CVE-2009-3279?
CVE-2009-3279 is caused by the use of the AES-256 cipher in plain CBC mode for creating LUKS partitions.
Can local users exploit CVE-2009-3279?
Yes, local users can exploit CVE-2009-3279 to obtain sensitive information via a watermark attack.