Hard-coded Credentials Vulnerability in Synology Calendar Software
CVE-2021-34812

5.8MEDIUM

Key Information:

Vendor
Synology
Vendor
CVE Published:
18 June 2021

Summary

A recently discovered vulnerability in Synology Calendar prior to version 2.4.0-0761 involves the use of hard-coded credentials within the php component. This flaw may allow remote attackers to exploit the system, potentially enabling them to gain unauthorized access and retrieve sensitive information through unspecified attack vectors.

Affected Version(s)

Synology Calendar < 2.4.0-0761

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.