Authentication Vulnerability in Synology Photo Station Affects User Credentials
CVE-2017-9552

7.8HIGH

Key Information:

Vendor
Synology
Vendor
CVE Published:
13 June 2017

Summary

A design flaw in the authentication mechanism of Synology Photo Station versions 6.0-2528 through 6.7.1-3419 allows local users to access and retrieve user credentials. The flaw arises from the usage of the synophoto_dsm_user program, which authenticates usernames and passwords through the command line. By sniffing the '/proc/*/cmdline' directory, unauthorized local users can capture sensitive login information, potentially compromising user accounts and sensitive data stored within the application.

Affected Version(s)

Synology Photo Station 6.0-2528 through 6.7.1-3419

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.