« Volver al listado

CVE-2013-6276

Estado: ModificadaCrítica (9.8)—

** NO COMPATIBLE CUANDO SE ASIGNÓ ** QNAP F_VioCard 2312 y F_VioGate 2308, presentan entradas embebidas en los archivos authorized_keys. NOTA: 1. Todos los modelos activos no están afectados. El último modelo afectado fue EOL desde 2010. 2. El mecanismo de autorización heredado ya no se adopta en todos los modelos activos

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6276",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-09T18:15:07.120",
  "references": [
    {
      "url": "http://firmware.re/vulns/acsa-2013-002.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://web.archive.org/web/20210320190014/http://firmware.re/vulns/acsa-2013-002.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://firmware.re/vulns/acsa-2013-002.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://web.archive.org/web/20210320190014/http://firmware.re/vulns/acsa-2013-002.php",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models"
    },
    {
      "lang": "es",
      "value": "** NO COMPATIBLE CUANDO SE ASIGNÓ ** QNAP F_VioCard 2312 y F_VioGate 2308, presentan entradas embebidas en los archivos authorized_keys. NOTA: 1. Todos los modelos activos no están afectados. El último modelo afectado fue EOL desde 2010. 2. El mecanismo de autorización heredado ya no se adopta en todos los modelos activos"
    }
  ],
  "lastModified": "2026-06-17T00:00:14.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:viocard-30_firmware:2312_2.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6684D14A-C19F-4059-BE95-DFEECB82C79C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:viocard-30:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2D1FFC14-6745-43D3-ABCC-DAABA83D50CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:viocard-100_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5417033-C06D-4C57-B612-40331463FDD7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:viocard-100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DC59C84A-35B0-4A31-8F4B-775C1F8C079B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:viocard-300_firmware:rc_b3722:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A75B8A8B-D810-4E67-A08B-E5D3788E3932"
            },
            {
              "criteria": "cpe:2.3:o:qnap:viocard-300_firmware:rs_b4631:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06907526-B04B-4E94-B9FB-5584392DFA2E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:viocard-300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C17C3D98-39BF-433A-BEF8-002F94F9823A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:viogate-340a_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "032AE80C-1764-43DB-BE88-083722BEE2AF"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:viogate-340a:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52AF1E36-B624-41DF-9057-81E510757F64"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:viogate-340_firmware:2308_2.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9AE0F94-2026-46F4-9611-168071A095D9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:viogate-340:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "966677D1-45FB-4363-AEF3-CDBB3DED8D2E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}