CVE-2023-2729 — Use of Insufficiently Random Values in Synology Diskstation Manager
Severity
7.5HIGHNVD
CNA5.9
EPSS
0.3%
top 48.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Description
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
🔴Vulnerability Details
2GHSA▶
GHSA-j384-2f78-m2qh: Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7↗2023-06-13
CVEList▶
CVE-2023-2729: Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7↗2023-06-13