Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qx3r-xm4v-rgrh

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.

EPSS

Процентиль: 23%
0.00074
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 5.5
nvd
больше 16 лет назад

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.

EPSS

Процентиль: 23%
0.00074
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-338