CRITICAL · 9.8

CVE-2013-6276

QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authoriza...

Vulnerability Description

QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QnapViocard-30 Firmware2312_2.1.0
QnapViocard-30-
QnapViocard-100 Firmware-
QnapViocard-100-
QnapViocard-300 Firmwarerc_b3722
QnapViocard-300-
QnapViogate-340A Firmware-
QnapViogate-340A-
QnapViogate-340 Firmware2308_2.1.0
QnapViogate-340-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6276?

CVE-2013-6276 is a vulnerability with a CVSS score of 9.8 (CRITICAL). QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authoriza...

How severe is CVE-2013-6276?

CVE-2013-6276 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2013-6276?

Check the references section above for vendor advisories and patch information. Affected products include: Qnap Viocard-30 Firmware, Qnap Viocard-30, Qnap Viocard-100 Firmware, Qnap Viocard-100, Qnap Viocard-300 Firmware.