CVE-2018-13291: Infoleak
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13291?
CVE-2018-13291 is classified as a high severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2018-13291?
To fix CVE-2018-13291, upgrade Synology DiskStation Manager to version 6.2.1-23824 or later.
Who is affected by CVE-2018-13291?
CVE-2018-13291 affects all Synology DiskStation Manager versions prior to 6.2.1-23824.
What type of vulnerability is CVE-2018-13291?
CVE-2018-13291 is an information exposure vulnerability that allows remote authenticated users to access sensitive configurations.
What are the consequences of CVE-2018-13291?
The consequences of CVE-2018-13291 include the potential unauthorized disclosure of sensitive information contained in mount.conf.