First published: Thu Oct 29 2020(Updated: )
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.3-25426-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27656 is a vulnerability that allows man-in-the-middle attackers to eavesdrop on authentication information of DNSExit in Synology DiskStation Manager (DSM) before version 6.2.3-25426-2.
CVE-2020-27656 has a severity rating of medium, with a score of 3.7.
Synology DiskStation Manager (DSM) versions before 6.2.3-25426-2 are affected by CVE-2020-27656.
Man-in-the-middle attackers can exploit CVE-2020-27656 to eavesdrop on authentication information of DNSExit by intercepting cleartext transmissions of sensitive data in DDNS.
Yes, updating Synology DiskStation Manager (DSM) to version 6.2.3-25426-2 or later will fix CVE-2020-27656.