Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1431

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2008-1431
Last Modified 05 Sep 2008 05:37:44
Published 20 Mar 2008 02:44:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2008-1431

Summary

RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.

Vulnerable Systems

Operating System

  • Raidsonic Technology Firmware 2.6.0-n


References

BID - 28264

BUGTRAQ - 20080316 raidsonic nas-4220 crypt disk key leak (stored in plain on unencrypted partition)

SECUNIA - 29401

SREASON - 3760


Last Updated: 27 May 2016 10:47:08