ZDI-23-658: (Pwn2Own) Synology DiskStation Manager api.php Authentication Bypass Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Synology Diskstation Manager
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-658?
The severity of ZDI-23-658 is critical due to its ability to allow remote attackers to bypass authentication.
2
How do I fix ZDI-23-658?
To fix ZDI-23-658, update your Synology DiskStation Manager to the latest security patch provided by Synology.
3
What systems are affected by ZDI-23-658?
ZDI-23-658 affects installations of Synology DiskStation Manager.
4
Can ZDI-23-658 be exploited remotely?
Yes, ZDI-23-658 can be exploited remotely without any authentication required.
5
Is authentication required to exploit ZDI-23-658?
No, authentication is not required to exploit the ZDI-23-658 vulnerability.