CVE-2018-13286Incorrect Default Permissions in Synology Diskstation Manager

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 69.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 13

Description

Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5synology/diskstation_managerunspecified6.2-23739-1
NVDsynology/diskstation_manager5.25.2-5967-8+3

🔴Vulnerability Details

2
GHSA
GHSA-5hf6-8rwq-jj93: Incorrect default permissions vulnerability in synouser2022-05-13
CVEList
CVE-2018-13286: Incorrect default permissions vulnerability in synouser2019-04-01
CVE-2018-13286 — Incorrect Default Permissions | cvebase