First published: Tue Nov 07 2017(Updated: )
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology CardDAV Server | <6.0.7-0085 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15887 is an improper restriction of excessive authentication attempts vulnerability in Synology CardDAV Server before version 6.0.7-0085.
CVE-2017-15887 allows remote attackers to obtain user credentials through a brute-force attack on the /principals endpoint in Synology CardDAV Server before version 6.0.7-0085.
CVE-2017-15887 has a severity rating of 9.8 (critical) based on the CVSS v3.0 scoring system.
To fix CVE-2017-15887, it is recommended to update Synology CardDAV Server to version 6.0.7-0085 or later.
More information about CVE-2017-15887 can be found on the Synology website at: https://www.synology.com/en-global/support/security/Synology_SA_17_64_CardDAV_Server