CVE-2017-12080: Infoleak
Published Dec 4, 2017
·Updated
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.
Affected Software
2 affected components
Synology Photo Station>=6.3<6.3-2970
Synology Photo Station>=6.8<6.8.1-3458
Event History
Dec 4, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-12080?
CVE-2017-12080 is an information exposure vulnerability in the default HTTP configuration file in Synology Photo Station.
2
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by using a .htaccess file to obtain sensitive system information.
3
Which versions of Synology Photo Station are affected by CVE-2017-12080?
Synology Photo Station versions before 6.8.1-3458 and before 6.3-2970 are affected by CVE-2017-12080.
4
What is the severity of CVE-2017-12080?
CVE-2017-12080 has a severity rating of medium with a score of 5.3.
5
Is there a fix available for CVE-2017-12080?
Yes, the fix for CVE-2017-12080 is available in Synology Photo Station version 6.8.1-3458 and version 6.3-2970.