CVE-2017-12076: Medium severity synology photos diskstation manager vulnerability
Published Aug 28, 2017
·Updated
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.
Affected Software
4 affected components
Synology Diskstation Manager<=6.1
Synology Diskstation Manager=6.1.1
Synology Diskstation Manager<=6.1
Synology Diskstation Manager=6.1.1
Event History
Aug 28, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12076?
The severity of CVE-2017-12076 is classified as medium, with a CVSS score of 4.9.
2
How do I fix CVE-2017-12076?
To fix CVE-2017-12076, upgrade Synology DiskStation Manager to version 6.1.1 or later.
3
What type of vulnerability is described in CVE-2017-12076?
CVE-2017-12076 describes an Uncontrolled Resource Consumption vulnerability allowing memory resource exhaustion.
4
Who is affected by CVE-2017-12076?
CVE-2017-12076 affects Synology DiskStation Manager versions up to 6.1.1-15088.
5
What can an attacker do with CVE-2017-12076?
An attacker can exploit CVE-2017-12076 to cause a denial of service by exhausting the machine's memory resources.