First published: Mon Apr 01 2019(Updated: )
Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via client-initiated renegotiation.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology MailPlus Server | <2.0.5-0606 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13296 is considered a high severity vulnerability due to its potential to allow denial-of-service attacks.
To fix CVE-2018-13296, update your Synology MailPlus Server to version 2.0.5-0606 or later.
CVE-2018-13296 is an uncontrolled resource consumption vulnerability related to TLS configuration.
Yes, CVE-2018-13296 can be exploited remotely by attackers through client-initiated renegotiation.
CVE-2018-13296 affects Synology MailPlus Server versions prior to 2.0.5-0606.