First published: Sun Mar 02 2014(Updated: )
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | =4.3-3810-1 | |
Synology DiskStation Manager | =4.3-3810-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2264 is considered a high severity vulnerability due to the hardcoded root password that can be exploited by attackers.
To fix CVE-2014-2264, update your Synology DiskStation Manager to a version that addresses this vulnerability and remove the hardcoded password.
CVE-2014-2264 affects users of Synology DiskStation Manager version 4.3-3810 update 1.
The impact of CVE-2014-2264 allows remote attackers to gain unauthorized access to the system through a VPN session.
CVE-2014-2264 was disclosed in 2014, highlighting the critical security flaw in Synology DiskStation Manager.