ID

VAR-200803-0434


CVE

CVE-2008-1431


TITLE

RaidSonic NAS-4220-B Vulnerability in obtaining encryption keys

Trust: 0.8

sources: JVNDB: JVNDB-2008-005603

DESCRIPTION

RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key. RaidSonic NAS-4220-B is prone to a vulnerability that can compromise encrypted data. This issue occurs because the key used by the device to encrypt hard-drive data is stored insecurely in the configuration partitions of each drive. Attackers with physical access to the NAS can exploit this issue to decrypt potentially sensitive information stored on the hard disks. This issue affects NAS-4220-B running firmware 2.6.0-n(2007-10-11). Other devices and firmware versions may also be affected. ---------------------------------------------------------------------- A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI has been released. The new version includes many new and advanced features, which makes it even easier to stay patched. Download and test it today: https://psi.secunia.com/ Read more about this new version: https://psi.secunia.com/?page=changelog ---------------------------------------------------------------------- TITLE: RaidSonic ICY BOX NAS-4220-B Insecure Storage of Encryption Key SECUNIA ADVISORY ID: SA29401 VERIFY ADVISORY: http://secunia.com/advisories/29401/ CRITICAL: Not critical IMPACT: Exposure of sensitive information WHERE: Local system OPERATING SYSTEM: RaidSonic ICY BOX NAS-4220-B http://secunia.com/product/17944/ DESCRIPTION: Collin Mulliner has reported a security issue in RaidSonic NAS-4220-B, which can be exploited by malicious people with physical access to the device to disclose potentially sensitive information. SOLUTION: Do not rely on the disk encryption feature. PROVIDED AND/OR DISCOVERED BY: Collin Mulliner ORIGINAL ADVISORY: http://www.mulliner.org/security/advisories/raidsonic_nas4220_crypt_disk_key_leak_09Mar2008.txt ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2008-1431 // JVNDB: JVNDB-2008-005603 // BID: 28264 // VULHUB: VHN-31556 // PACKETSTORM: 64754

AFFECTED PRODUCTS

vendor:raidsonicmodel: - scope:eqversion:2.6.0-n

Trust: 2.4

vendor:raidsonicmodel:technology nas-4220-b 2.6.0-nscope:eqversion:(2007-10-11)

Trust: 0.3

sources: BID: 28264 // JVNDB: JVNDB-2008-005603 // CNNVD: CNNVD-200803-356 // NVD: CVE-2008-1431

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-1431
value: LOW

Trust: 1.0

NVD: CVE-2008-1431
value: LOW

Trust: 0.8

CNNVD: CNNVD-200803-356
value: LOW

Trust: 0.6

VULHUB: VHN-31556
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2008-1431
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-31556
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-31556 // JVNDB: JVNDB-2008-005603 // CNNVD: CNNVD-200803-356 // NVD: CVE-2008-1431

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-31556 // JVNDB: JVNDB-2008-005603 // NVD: CVE-2008-1431

THREAT TYPE

local

Trust: 0.9

sources: BID: 28264 // CNNVD: CNNVD-200803-356

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-200803-356

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-005603

PATCH

title:Top Pageurl:http://www.raidsonic.de/

Trust: 0.8

sources: JVNDB: JVNDB-2008-005603

EXTERNAL IDS

db:NVDid:CVE-2008-1431

Trust: 2.8

db:BIDid:28264

Trust: 2.0

db:SECUNIAid:29401

Trust: 1.8

db:SREASONid:3760

Trust: 1.7

db:JVNDBid:JVNDB-2008-005603

Trust: 0.8

db:CNNVDid:CNNVD-200803-356

Trust: 0.7

db:BUGTRAQid:20080316 RAIDSONIC NAS-4220 CRYPT DISK KEY LEAK (STORED IN PLAIN ON UNENCRYPTED PARTITION)

Trust: 0.6

db:VULHUBid:VHN-31556

Trust: 0.1

db:PACKETSTORMid:64754

Trust: 0.1

sources: VULHUB: VHN-31556 // BID: 28264 // JVNDB: JVNDB-2008-005603 // PACKETSTORM: 64754 // CNNVD: CNNVD-200803-356 // NVD: CVE-2008-1431

REFERENCES

url:http://www.securityfocus.com/bid/28264

Trust: 1.7

url:http://secunia.com/advisories/29401

Trust: 1.7

url:http://securityreason.com/securityalert/3760

Trust: 1.7

url:http://www.securityfocus.com/archive/1/489690/100/0/threaded

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-1431

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-1431

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/489690/100/0/threaded

Trust: 0.6

url:http://www.raidsonic.de/en/pages/home/home.php

Trust: 0.3

url:/archive/1/489690

Trust: 0.3

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:https://psi.secunia.com/?page=changelog

Trust: 0.1

url:https://psi.secunia.com/

Trust: 0.1

url:http://www.mulliner.org/security/advisories/raidsonic_nas4220_crypt_disk_key_leak_09mar2008.txt

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/29401/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:http://secunia.com/product/17944/

Trust: 0.1

sources: VULHUB: VHN-31556 // BID: 28264 // JVNDB: JVNDB-2008-005603 // PACKETSTORM: 64754 // CNNVD: CNNVD-200803-356 // NVD: CVE-2008-1431

CREDITS

Collin R. Mulliner discovered this issue.

Trust: 0.9

sources: BID: 28264 // CNNVD: CNNVD-200803-356

SOURCES

db:VULHUBid:VHN-31556
db:BIDid:28264
db:JVNDBid:JVNDB-2008-005603
db:PACKETSTORMid:64754
db:CNNVDid:CNNVD-200803-356
db:NVDid:CVE-2008-1431

LAST UPDATE DATE

2025-04-10T23:25:38.114000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-31556date:2018-10-11T00:00:00
db:BIDid:28264date:2015-05-07T17:32:00
db:JVNDBid:JVNDB-2008-005603date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200803-356date:2008-09-05T00:00:00
db:NVDid:CVE-2008-1431date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-31556date:2008-03-20T00:00:00
db:BIDid:28264date:2008-03-17T00:00:00
db:JVNDBid:JVNDB-2008-005603date:2012-12-20T00:00:00
db:PACKETSTORMid:64754date:2008-03-20T20:39:31
db:CNNVDid:CNNVD-200803-356date:2008-03-20T00:00:00
db:NVDid:CVE-2008-1431date:2008-03-20T18:44:00