CVE-2017-12080Sensitive Information Exposure in Synology Photo Station

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 54.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateMay 13

Description

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDsynology/photo_station6.36.3-2970+1
CVEListV5synology/photo_stationbefore 6.3-2970, before 6.8.1-3458+1

🔴Vulnerability Details

2
GHSA
GHSA-cqcj-crrg-47xp: An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 62022-05-13
CVEList
CVE-2017-12080: An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 62017-12-04
CVE-2017-12080 — Sensitive Information Exposure | cvebase