Sensitive Information Exposure in Synology Note Station Client
CVE-2022-27619

6.8MEDIUM

Key Information:

Vendor
Synology
Vendor
CVE Published:
3 August 2022

Summary

A vulnerability exists in the Synology Note Station Client prior to version 2.2.2-609 that allows man-in-the-middle attackers to intercept sensitive data due to cleartext transmission in authentication management. This could potentially expose important user information, leading to unauthorized access or data theft. The vulnerability can be exploited through unspecified vectors, emphasizing the need for secure communications in software applications.

Affected Version(s)

Synology Note Station Client < 2.2.2-609

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.