CVE-2009-3200
Summary
| CVE | CVE-2009-3200 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-21 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:C/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qnap | Ts-239 Pro Turbo Nas | 2.1.7_0613 | All | All | All |
| Hardware | Qnap | Ts-239 Pro Turbo Nas | 3.1.0_0627 | All | All | All |
| Hardware | Qnap | Ts-239 Pro Turbo Nas | 3.1.1_0815 | All | All | All |
| Hardware | Qnap | Ts-639 Pro Turbo Nas | 2.1.7_0613 | All | All | All |
| Hardware | Qnap | Ts-639 Pro Turbo Nas | 3.1.0_0627 | All | All | All |
| Hardware | Qnap | Ts-639 Pro Turbo Nas | 3.1.1_0815 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - QNAP Storage Devices Lets Local Users Decrypt Files on the Target Device | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| QNAP NAS Community Forum • View topic - Faulty disk encryption implementation? | af854a3a-2127-422b-91ae-364da2661108 | forum.qnap.com | |
| www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt | af854a3a-2127-422b-91ae-364da2661108 | www.baseline-security.de | Exploit |
| QNAP NAS Community Forum • View topic - TS-509 Filesystem AES Encryption Passphrase | af854a3a-2127-422b-91ae-364da2661108 | forum.qnap.com | |
| Qnap Storage Devices Unauthorized Access Vulnerability and Security Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| QNAP Devices Hard Disk Encryption Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.