CVE-2018-8916: High severity Synology Diskstation Manager vulnerability
Published Jun 8, 2018
·Updated
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
Affected Software
2 affected components
Synology Diskstation Manager<6.2-23739
Synology Diskstation Manager<6.2-23739
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8916?
CVE-2018-8916 is considered a high-severity vulnerability due to its potential impact on user account security.
2
How do I fix CVE-2018-8916?
To fix CVE-2018-8916, upgrade Synology DiskStation Manager to version 6.2-23739 or later.
3
Who is affected by CVE-2018-8916?
Remote authenticated users of Synology DiskStation Manager versions prior to 6.2-23739 are affected by CVE-2018-8916.
4
What type of vulnerability is CVE-2018-8916?
CVE-2018-8916 is an unverified password change vulnerability that allows remote authenticated users to reset passwords without verification.
5
Is CVE-2018-8916 a remote vulnerability?
Yes, CVE-2018-8916 can be exploited remotely by authenticated users of the affected versions.