ZDI-CAN-19828: ZDI-23-659: (Pwn2Own) Synology DiskStation Manager dnsauth.php Missing Authentication Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Synology DiskStation Manager. This vulnerability does not require authentication, but does require some user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19828?
The severity of ZDI-CAN-19828 is considered significant due to its potential for unauthorized information disclosure.
How do I fix ZDI-CAN-19828?
To fix ZDI-CAN-19828, update your Synology DiskStation Manager to the latest version provided by Synology.
What is the impact of ZDI-CAN-19828?
ZDI-CAN-19828 allows remote attackers to disclose sensitive information, potentially compromising the security of affected installations.
Is authentication required for ZDI-CAN-19828 exploitation?
No, ZDI-CAN-19828 does not require authentication, making it particularly concerning for users.
What kind of user interaction is needed for ZDI-CAN-19828?
ZDI-CAN-19828 requires some form of user interaction, which could involve actions like opening a malicious link.