CVE-2020-27650: Medium severity Synology Diskstation Manager vulnerability
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27650?
CVE-2020-27650 is a vulnerability in Synology DiskStation Manager (DSM) before version 6.2.3-25426-2 that does not set the Secure flag for the session cookie in an HTTPS session.
How does CVE-2020-27650 impact users?
CVE-2020-27650 makes it easier for remote attackers to capture the session cookie by intercepting its transmission within an HTTP session.
Which software versions are affected by CVE-2020-27650?
Synology DiskStation Manager (DSM) versions before 6.2.3-25426-2 are affected by CVE-2020-27650.
What is the severity of CVE-2020-27650?
CVE-2020-27650 has a severity level of medium (3.7).
How can users fix CVE-2020-27650?
To fix CVE-2020-27650, users should update to version 6.2.3-25426-2 or later of Synology DiskStation Manager (DSM).