Sensitive Information Vulnerability in Synology DiskStation Manager
CVE-2021-26565
5.9MEDIUM
Key Information:
- Vendor
- Synology
- Vendor
- CVE Published:
- 26 February 2021
Summary
A vulnerability exists in Synology DiskStation Manager's synorelayd that allows for cleartext transmission of sensitive information. Attackers can exploit this vulnerability by conducting man-in-the-middle attacks during HTTP sessions, potentially compromising user credentials and other sensitive data. It is essential for users to ensure they are using updated versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
Synology DiskStation Manager (DSM) < 6.2.3-25426-3
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved