First published: Thu Oct 29 2020(Updated: )
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.3-25426-2 | |
Synology Skynas Firmware | <6.2.3-25426 | |
Synology Skynas |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27648 is an improper certificate validation vulnerability in the OpenVPN client in Synology DiskStation Manager (DSM) before version 6.2.3-25426-2.
CVE-2020-27648 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
If your Synology DiskStation Manager version is before 6.2.3-25426-2, then it is vulnerable to CVE-2020-27648.
CVE-2020-27648 has a severity rating of critical.
To fix the CVE-2020-27648 vulnerability, you should update your Synology DiskStation Manager to version 6.2.3-25426-2 or later.