First published: Sun Mar 31 2019(Updated: )
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | >=1.1<1.1.7-6941-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13292 is an information exposure vulnerability in Synology Router Manager (SRM) that allows remote authenticated users to obtain sensitive information.
CVE-2018-13292 allows remote authenticated users to access sensitive information through the world readable configuration file in Synology Router Manager (SRM).
CVE-2018-13292 has a severity rating of medium with a CVSS score of 4.3.
To fix CVE-2018-13292 in Synology Router Manager, it is recommended to update to version 1.1.7-6941-2 or later, as specified in the security advisory provided by Synology.
You can find more information about CVE-2018-13292 in the security advisory provided by Synology at the following URL: https://www.synology.com/security/advisory/Synology_SA_18_48