PT-2021-8376 · Qnap · Qnap F Viocard 2312+1
Andrei Costin
·
Published
2021-08-09
·
Updated
2024-08-06
·
CVE-2013-6276
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP F VioCard 2312 (affected versions not specified)
QNAP F VioGate 2308 (affected versions not specified)
Description
The issue concerns hardcoded entries in authorized keys files. It is noted that all active models are not affected, and the last affected model was end-of-life since 2010. Additionally, the legacy authorization mechanism is no longer used in active models.
Recommendations
For QNAP F VioCard 2312, consider removing the hardcoded entries in authorized keys files as a mitigation measure.
For QNAP F VioGate 2308, consider removing the hardcoded entries in authorized keys files as a mitigation measure.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnap F Viocard 2312
Qnap F Viogate 2308