CVE-2017-9553: High severity Synology Diskstation Manager vulnerability
Published Jul 24, 2017
·Updated
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
Affected Software
2 affected components
Synology Diskstation Manager<=6.1.1-15101-4
Synology Diskstation Manager<=6.1.1-15101-4
Event History
Jul 24, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9553?
The severity of CVE-2017-9553 is rated as high with a score of 7.5.
2
How do I fix CVE-2017-9553?
To fix CVE-2017-9553, update Synology DiskStation Manager to version 6.1.3-15152 or later.
3
What access does CVE-2017-9553 allow an attacker?
CVE-2017-9553 allows remote attackers to bypass the encryption protection mechanism.
4
Which versions of Synology DiskStation Manager are affected by CVE-2017-9553?
Versions of Synology DiskStation Manager prior to 6.1.3-15152 are affected by CVE-2017-9553.
5
Is there a workaround for CVE-2017-9553?
There are no official workarounds for CVE-2017-9553; upgrading the software is recommended.