First published: Sun Mar 31 2019(Updated: )
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | <1.1.7-6941-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-13287.
The title of this vulnerability is 'Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before…'
The affected software is Synology Router Manager (SRM) before version 1.1.7-6941-1.
The severity of CVE-2018-13287 is medium.
Remote authenticated users can exploit this vulnerability to obtain sensitive information via the world-readable configuration.