CVE-2018-8919: Infoleak
Published Dec 24, 2018
·Updated
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
Affected Software
2 affected components
Synology Diskstation Manager<6.1.6-15266
Synology Diskstation Manager<6.1.6-15266
Event History
Dec 24, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-8919?
CVE-2018-8919 is considered a high severity vulnerability due to the potential for remote attackers to steal user credentials.
2
How do I fix CVE-2018-8919?
To fix CVE-2018-8919, update Synology DiskStation Manager to version 6.1.6-15266 or later immediately.
3
What software versions are affected by CVE-2018-8919?
CVE-2018-8919 affects all versions of Synology DiskStation Manager prior to 6.1.6-15266.
4
What type of vulnerability is CVE-2018-8919?
CVE-2018-8919 is classified as an information exposure vulnerability.
5
What can attackers do with CVE-2018-8919?
Attackers exploiting CVE-2018-8919 can gain unauthorized access to user credentials through unspecified vectors.