First published: Mon Jul 24 2017(Updated: )
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | <=6.1.1-15101-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9553 is rated as high with a score of 7.5.
To fix CVE-2017-9553, update Synology DiskStation Manager to version 6.1.3-15152 or later.
CVE-2017-9553 allows remote attackers to bypass the encryption protection mechanism.
Versions of Synology DiskStation Manager prior to 6.1.3-15152 are affected by CVE-2017-9553.
There are no official workarounds for CVE-2017-9553; upgrading the software is recommended.