CVE-2020-27655: Critical severity synology router manager vulnerability
Published Oct 29, 2020
·Updated
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
Affected Software
1 affected component
Synology Router Manager>=1.2<1.2.4-8081
Event History
Oct 29, 2020
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-27655.
2
What is the severity of CVE-2020-27655?
The severity of CVE-2020-27655 is critical.
3
How does CVE-2020-27655 affect Synology Router Manager?
CVE-2020-27655 allows remote attackers to access restricted resources in Synology Router Manager (SRM) before version 1.2.4-8081 via inbound QuickConnect traffic.
4
What is the affected software of CVE-2020-27655?
The affected software of CVE-2020-27655 is Synology Router Manager (SRM) before version 1.2.4-8081.
5
Where can I find more information about CVE-2020-27655?
You can find more information about CVE-2020-27655 in the Synology security advisory (Synology_SA_20_14) and the Talos Intelligence vulnerability report (TALOS-2020-1066).