CVE-2017-9552: High severity Synology Photo Station vulnerability
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophotodsmuser program to authenticate username and password by "synophotodsmuser --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc//cmdline".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9552?
CVE-2017-9552 has a medium severity rating due to its potential to expose user credentials.
How do I fix CVE-2017-9552?
To fix CVE-2017-9552, update Synology Photo Station to the latest version where the vulnerability is addressed.
Who is affected by CVE-2017-9552?
Local users of Synology Photo Station versions 6.0-2528 through 6.7.1-3419 are affected by CVE-2017-9552.
What is the main issue caused by CVE-2017-9552?
The main issue caused by CVE-2017-9552 is a design flaw in authentication that allows local users to obtain credentials.
Is there a workaround for CVE-2017-9552?
There are no known workarounds for CVE-2017-9552, so updating to a patched version is recommended.