First published: Mon Apr 01 2019(Updated: )
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photos Diskstation Manager | >=5.2<5.2-5967-8 | |
Synology Photos Diskstation Manager | >=6.0<6.0.3-8754-8 | |
Synology Photos Diskstation Manager | >=6.1<6.1.7-15284-1 | |
Synology Photos Diskstation Manager | >=6.2<6.2-23739-1 | |
Synology Photos Diskstation Manager | >=5.2<5.2-5967-8 | |
Synology Photos Diskstation Manager | >=6.0<6.0.3-8754-8 | |
Synology Photos Diskstation Manager | >=6.1<6.1.7-15284-1 | |
Synology Photos Diskstation Manager | >=6.2<6.2-23739-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13286 has a medium severity rating due to its potential impact on sensitive information disclosure.
To fix CVE-2018-13286, update your Synology Diskstation Manager to version 6.2-23739-1 or later.
CVE-2018-13286 affects all versions of Synology Diskstation Manager prior to 6.2-23739-1.
CVE-2018-13286 is an incorrect default permissions vulnerability that allows unauthorized access to configuration files.
Yes, CVE-2018-13286 can be exploited by remote authenticated users to gain access to sensitive information.