ZDI-CAN-19829: ZDI-23-660: (Pwn2Own) Synology DiskStation Manager Serv.php Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Synology DiskStation Manager. This vulnerability does not require authentication, but does require some user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19829?
The severity of ZDI-CAN-19829 is considered high due to the potential for remote attackers to bypass authentication.
How can I fix ZDI-CAN-19829?
To fix ZDI-CAN-19829, update your Synology DiskStation Manager to the latest security patch provided by Synology.
Who is affected by ZDI-CAN-19829?
Users of Synology DiskStation Manager are affected by ZDI-CAN-19829, especially those with unpatched installations.
Does ZDI-CAN-19829 require authentication?
ZDI-CAN-19829 does not require prior authentication to exploit, making it more critical.
What type of attack is possible with ZDI-CAN-19829?
ZDI-CAN-19829 allows remote attackers to bypass authentication, potentially granting them unauthorized access.