LOW · 2.1

CVE-2010-3684

The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive informatio...

Vulnerability Description

The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SynologyDsm2.2-0942
SynologyDisk Station Ds1010\+All versions
SynologyDisk Station Ds109All versions
SynologyDisk Station Ds110\+All versions
SynologyDisk Station Ds110JAll versions
SynologyDisk Station Ds209All versions
SynologyDisk Station Ds210\+All versions
SynologyDisk Station Ds210JAll versions
SynologyDisk Station Ds409SlimAll versions
SynologyDisk Station Ds410All versions
SynologyDisk Station Ds410JAll versions
SynologyDisk Station Ds411\+All versions
SynologyDisk Station Ds710\+All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3684?

CVE-2010-3684 is a vulnerability with a CVSS score of 2.1 (LOW). The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive informatio...

How severe is CVE-2010-3684?

CVE-2010-3684 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3684?

Check the references section above for vendor advisories and patch information. Affected products include: Synology Dsm, Synology Disk Station Ds1010\+, Synology Disk Station Ds109, Synology Disk Station Ds110\+, Synology Disk Station Ds110J.