CVE-2020-27649: Critical severity synology router manager vulnerability
Published Oct 29, 2020
·Updated
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Synology Router Manager>=1.2<1.2.4-8081
Event History
Oct 29, 2020
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-27649.
2
What is the title of this vulnerability?
The title of this vulnerability is "Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081."
3
What is the severity of CVE-2020-27649?
The severity of CVE-2020-27649 is critical.
4
What software is affected by CVE-2020-27649?
The Synology Router Manager (SRM) software versions before 1.2.4-8081 are affected by CVE-2020-27649.
5
How can I fix CVE-2020-27649?
To fix CVE-2020-27649, users should update their Synology Router Manager (SRM) software to version 1.2.4-8081 or later.