Vulnerability Details CVE-2009-3279
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.4%
CVSS Severity
CVSS v2 Score 4.9
Products affected by CVE-2009-3279
-
cpe:2.3:h:qnap:ts-239_pro_turbo_nas:2.1.7_0613
-
cpe:2.3:h:qnap:ts-239_pro_turbo_nas:3.1.0_0627
-
cpe:2.3:h:qnap:ts-239_pro_turbo_nas:3.1.1_0815
-
cpe:2.3:h:qnap:ts-639_pro_turbo_nas:2.1.7_0613
-
cpe:2.3:h:qnap:ts-639_pro_turbo_nas:3.1.0_0627
-
cpe:2.3:h:qnap:ts-639_pro_turbo_nas:3.1.1_0815