CVE-2021-26565: High severity synology photos diskstation manager vulnerability
Published Feb 26, 2021
·Updated
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.
Affected Software
14 affected components
Synology Diskstation Manager<6.2.3-25426-3
All of the following
Synology Vs960hd Firmware
Synology Vs960hd
All of the following
Synology Skynas Firmware
Synology Skynas
All of the following
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Synology Diskstation Manager<6.2.3-25426-3
Synology Vs960hd Firmware
Synology Vs960hd
Synology Skynas Firmware
Synology Skynas
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Event History
Feb 26, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-26565.
2
What is the severity rating of CVE-2021-26565?
The severity rating of CVE-2021-26565 is 5.9 (High).
3
What is affected by CVE-2021-26565?
Synology DiskStation Manager (DSM) before 6.2.3-25426-3 and Synology Vs960hd Firmware are affected by CVE-2021-26565.
4
How can an attacker exploit CVE-2021-26565?
An attacker can exploit CVE-2021-26565 by performing a man-in-the-middle attack to obtain sensitive information via an HTTP session.
5
Are Synology Vs960hd and Synology Skynas vulnerable to CVE-2021-26565?
No, Synology Vs960hd and Synology Skynas are not vulnerable to CVE-2021-26565.