{"api_version":"1","generated_at":"2026-07-23T07:49:14+00:00","cve":"CVE-2009-3200","urls":{"html":"https://cve.report/CVE-2009-3200","api":"https://cve.report/api/cve/CVE-2009-3200.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3200","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3200"},"summary":{"title":"CVE-2009-3200","description":"The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-21 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:P/A:P","baseScore":5.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53391","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53391","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022916","name":"http://www.securitytracker.com/id?1022916","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - QNAP Storage Devices Lets Local Users Decrypt Files on the Target Device","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341","name":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"QNAP NAS Community Forum • View topic - Faulty disk encryption implementation?","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt","name":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346","name":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"QNAP NAS Community Forum • View topic - TS-509 Filesystem AES Encryption Passphrase","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36467","name":"http://www.securityfocus.com/bid/36467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Qnap Storage Devices Unauthorized Access Vulnerability and Security Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/36793","name":"http://secunia.com/advisories/36793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"QNAP Devices Hard Disk Encryption Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/506607/100/0/threaded","name":"http://www.securityfocus.com/archive/1/506607/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3200","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3200","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-239_pro_turbo_nas","cpe6":"2.1.7_0613","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-239_pro_turbo_nas","cpe6":"3.1.0_0627","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-239_pro_turbo_nas","cpe6":"3.1.1_0815","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-639_pro_turbo_nas","cpe6":"2.1.7_0613","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-639_pro_turbo_nas","cpe6":"3.1.0_0627","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3200","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qnap","cpe5":"ts-639_pro_turbo_nas","cpe6":"3.1.1_0815","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:14:56.419Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt"},{"name":"36793","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36793"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346"},{"name":"qnap-backupkey-weak-security(53391)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53391"},{"name":"20090918 Advisory: Crypto backdoor in Qnap storage devices (CVE-2009-3200)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/506607/100/0/threaded"},{"name":"36467","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36467"},{"name":"1022916","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022916"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt"},{"name":"36793","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36793"},{"tags":["x_refsource_MISC"],"url":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341"},{"tags":["x_refsource_MISC"],"url":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346"},{"name":"qnap-backupkey-weak-security(53391)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53391"},{"name":"20090918 Advisory: Crypto backdoor in Qnap storage devices (CVE-2009-3200)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/506607/100/0/threaded"},{"name":"36467","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36467"},{"name":"1022916","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022916"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3200","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt","refsource":"MISC","url":"http://www.baseline-security.de/downloads/BSC-Qnap_Crypto_Backdoor-CVE-2009-3200.txt"},{"name":"36793","refsource":"SECUNIA","url":"http://secunia.com/advisories/36793"},{"name":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341","refsource":"MISC","url":"http://forum.qnap.com/viewtopic.php?f=12&t=12104&start=10#p63341"},{"name":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346","refsource":"MISC","url":"http://forum.qnap.com/viewtopic.php?f=11&t=11214&start=20#p63346"},{"name":"qnap-backupkey-weak-security(53391)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53391"},{"name":"20090918 Advisory: Crypto backdoor in Qnap storage devices (CVE-2009-3200)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/506607/100/0/threaded"},{"name":"36467","refsource":"BID","url":"http://www.securityfocus.com/bid/36467"},{"name":"1022916","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022916"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3200","datePublished":"2009-09-21T19:00:00.000Z","dateReserved":"2009-09-15T00:00:00.000Z","dateUpdated":"2024-08-07T06:14:56.419Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-21 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:P/A:P","baseScore":5.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":8.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-239_pro_turbo_nas:2.1.7_0613:*:*:*:*:*:*:*","matchCriteriaId":"5EE9055C-121F-4DB7-8C31-0C25860EB956"},{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-239_pro_turbo_nas:3.1.0_0627:*:*:*:*:*:*:*","matchCriteriaId":"DBD938AD-4FF6-43F7-BDBA-C751DBE670F9"},{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-239_pro_turbo_nas:3.1.1_0815:*:*:*:*:*:*:*","matchCriteriaId":"5D3675EC-CB39-4D51-9D38-D921A67F5085"},{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-639_pro_turbo_nas:2.1.7_0613:*:*:*:*:*:*:*","matchCriteriaId":"8C6B1151-66DD-41AC-BCE2-076B72738CF0"},{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-639_pro_turbo_nas:3.1.0_0627:*:*:*:*:*:*:*","matchCriteriaId":"8BE092C1-DE91-4DE2-90CB-7A3BD2B84B0A"},{"vulnerable":true,"criteria":"cpe:2.3:h:qnap:ts-639_pro_turbo_nas:3.1.1_0815:*:*:*:*:*:*:*","matchCriteriaId":"EF79B187-CD61-45B6-9D71-3C73D9490970"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3200","Ordinal":"1","Title":"CVE-2009-3200","CVE":"CVE-2009-3200","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3200","Ordinal":"1","NoteData":"The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.","Type":"Description","Title":"CVE-2009-3200"},{"CveYear":"2009","CveId":"3200","Ordinal":"2","NoteData":"2009-09-21","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3200","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}