First published: Thu Oct 29 2020(Updated: )
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | =6.2.3_25426 | |
Synology Router Manager | >=1.2<1.2.4-8081 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27653 is an algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081.
CVE-2020-27653 affects Synology DiskStation Manager version 6.2.3_25426.
CVE-2020-27653 affects Synology Router Manager versions 1.2 to 1.2.4-8081.
CVE-2020-27653 has a severity rating of 8.3 (high).
To fix CVE-2020-27653, update Synology Router Manager to version 1.2.4-8081 or later.