First published: Wed Sep 29 2010(Updated: )
The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Dsm | =2.2-0942 | |
Synology Dsm | =2.2-1041 | |
Synology Dsm | =2.2-1042 | |
Synology Dsm | =2.2-1045 | |
Synology Dsm | =2.3-1139 | |
Synology Dsm | =2.3-1141 | |
Synology Dsm | =2.3-1144 | |
Synology Dsm | =2.3-1157 | |
Synology Dsm | =2.3-1161 | |
Synology Disk Station Ds1010\+ | ||
Synology Disk Station Ds109 | ||
Synology Disk Station Ds110\+ | ||
Synology Disk Station Ds110j | ||
Synology Disk Station Ds209 | ||
Synology Disk Station Ds210\+ | ||
Synology Disk Station Ds210j | ||
Synology Disk Station Ds409slim | ||
Synology Disk Station Ds410 | ||
Synology Disk Station Ds410j | ||
Synology Disk Station Ds411\+ | ||
Synology Disk Station Ds710\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3684 has a medium severity rating due to its potential to expose sensitive information.
To fix CVE-2010-3684, you should update the Synology Disk Station firmware to the latest version that addresses this vulnerability.
CVE-2010-3684 affects Synology Disk Station DSM 2.x versions, specifically 2.2-0942, 2.2-1041, 2.2-1042, 2.2-1045, and 2.3-1139 to 2.3-1161.
CVE-2010-3684 operates by logging passwords to the web interface on unsuccessful FTP login attempts, which can be accessed by local users.
Local users with access to the Synology Disk Station systems running affected versions are at risk from CVE-2010-3684.