CVE-2023-2729Use of Insufficiently Random Values in Synology Diskstation Manager

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.3%
top 48.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

CVEListV5synology/diskstation_manager7.27.2-64561+3
NVDsynology/diskstation_manager6.27.2-64561
NVDsynology/router_manager1.21.3.1-9346+1
CVEListV5synology/synology_router_manager1.31.3.*+1

🔴Vulnerability Details

2
GHSA
GHSA-j384-2f78-m2qh: Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 72023-06-13
CVEList
CVE-2023-2729: Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 72023-06-13