CVE-2020-27656: Medium severity Synology Diskstation Manager vulnerability
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27656?
CVE-2020-27656 is a vulnerability that allows man-in-the-middle attackers to eavesdrop on authentication information of DNSExit in Synology DiskStation Manager (DSM) before version 6.2.3-25426-2.
How severe is CVE-2020-27656?
CVE-2020-27656 has a severity rating of medium, with a score of 3.7.
Which software versions are affected by CVE-2020-27656?
Synology DiskStation Manager (DSM) versions before 6.2.3-25426-2 are affected by CVE-2020-27656.
How can man-in-the-middle attackers exploit this vulnerability?
Man-in-the-middle attackers can exploit CVE-2020-27656 to eavesdrop on authentication information of DNSExit by intercepting cleartext transmissions of sensitive data in DDNS.
Is there a fix for CVE-2020-27656?
Yes, updating Synology DiskStation Manager (DSM) to version 6.2.3-25426-2 or later will fix CVE-2020-27656.