CVE-2021-26560Cleartext Transmission of Sensitive Info in Synology Diskstation Manager

Severity
7.4HIGHNVD
CNA9.0
EPSS
0.2%
top 62.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-3wrg-wf8p-659h: Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 62022-05-24
CVEList
CVE-2021-26560: Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 62021-02-26

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager2021-04-20
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager2021-04-20
CVE-2021-26560 — Synology vulnerability | cvebase