CVE-2021-26565Cleartext Transmission of Sensitive Info in Synology Diskstation Manager

Severity
5.9MEDIUMNVD
CNA8.3
EPSS
0.3%
top 45.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-8rp4-gqh3-jpxm: Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 62022-05-24
CVEList
CVE-2021-26565: Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 62021-02-26

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager2021-04-20
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager2021-04-20
CVE-2021-26565 — Synology vulnerability | cvebase