First published: Thu Oct 29 2020(Updated: )
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.3-25426-2 | |
Synology Skynas Firmware | <6.2.3-25426 | |
Synology Skynas |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-27652.
The title of this vulnerability is 'Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3...'
The severity of CVE-2020-27652 is high.
This vulnerability affects Synology DiskStation Manager versions before 6.2.3-25426-2.
An attacker can exploit this vulnerability by performing a man-in-the-middle attack to spoof servers and obtain sensitive information.