CVE-2017-15887: Critical severity synology carddav server vulnerability
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15887?
CVE-2017-15887 is an improper restriction of excessive authentication attempts vulnerability in Synology CardDAV Server before version 6.0.7-0085.
How does CVE-2017-15887 affect Synology CardDAV Server?
CVE-2017-15887 allows remote attackers to obtain user credentials through a brute-force attack on the /principals endpoint in Synology CardDAV Server before version 6.0.7-0085.
What is the severity of CVE-2017-15887?
CVE-2017-15887 has a severity rating of 9.8 (critical) based on the CVSS v3.0 scoring system.
How can I fix CVE-2017-15887?
To fix CVE-2017-15887, it is recommended to update Synology CardDAV Server to version 6.0.7-0085 or later.
Where can I find more information about CVE-2017-15887?
More information about CVE-2017-15887 can be found on the Synology website at: https://www.synology.com/en-global/support/security/Synology_SA_17_64_CardDAV_Server