CVE-2022-27619: Medium severity Synology Note Station vulnerability
Published Aug 3, 2022
·Updated
Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
Synology Note Station<2.2.2-609
Event History
Aug 3, 2022
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-27619.
2
What is the severity of CVE-2022-27619?
The severity of CVE-2022-27619 is medium.
3
What software is affected by CVE-2022-27619?
The Synology Note Station Client version up to 2.2.2-609 is affected by CVE-2022-27619.
4
How can a man-in-the-middle attacker exploit CVE-2022-27619?
A man-in-the-middle attacker can exploit CVE-2022-27619 to obtain sensitive information by intercepting cleartext transmission in authentication management.
5
Is there a fix available for CVE-2022-27619?
Yes, a fix is available for CVE-2022-27619. Please refer to the Synology security advisory for more information.