CVE-2021-26564: High severity synology photos diskstation manager vulnerability
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26564?
CVE-2021-26564 is a vulnerability that allows man-in-the-middle attackers to spoof servers via an HTTP session.
How severe is CVE-2021-26564?
CVE-2021-26564 has a severity score of 8.7, which is classified as high severity.
What software is affected by CVE-2021-26564?
Synology DiskStation Manager (DSM) before 6.2.3-25426-3 and Synology Vs960hd Firmware are affected by CVE-2021-26564.
How can man-in-the-middle attacks be prevented?
To prevent man-in-the-middle attacks, ensure that you are using secure protocols such as HTTPS, regularly update your software and devices, and use strong and unique passwords.
Where can I find more information about CVE-2021-26564?
You can find more information about CVE-2021-26564 at the official Synology security advisory (https://www.synology.com/security/advisory/Synology_SA_20_26) and the Talos Intelligence vulnerability report (https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1160).