Vulnerability Description
RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Raidsonic Technology | Firmware | 2.6.0-n |
| Raidsonic Technology | Nas-4220-B | 2.6.0-n |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/29401Vendor Advisory
- http://securityreason.com/securityalert/3760
- http://www.securityfocus.com/archive/1/489690/100/0/threaded
- http://www.securityfocus.com/bid/28264
- http://secunia.com/advisories/29401Vendor Advisory
- http://securityreason.com/securityalert/3760
- http://www.securityfocus.com/archive/1/489690/100/0/threaded
- http://www.securityfocus.com/bid/28264
FAQ
What is CVE-2008-1431?
CVE-2008-1431 is a vulnerability with a CVSS score of 2.1 (LOW). RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
How severe is CVE-2008-1431?
CVE-2008-1431 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1431?
Check the references section above for vendor advisories and patch information. Affected products include: Raidsonic Technology Firmware, Raidsonic Technology Nas-4220-B.