Exposure of private information in Synology Photo Station by Synology
CVE-2017-16769
5.3MEDIUM
Summary
A security flaw in Synology Photo Station version 6.8.1-3458 allows remote attackers to exploit the application's map viewer mode. This vulnerability enables unauthorized access to sensitive metadata from password-protected photographs, potentially exposing private information about the images and their locations. Consequently, users could face significant privacy risks if their data is improperly accessed.
Affected Version(s)
Synology Photo Station 6.8.1-3458
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved