Vulnerability Description
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Diskstation Manager | 4.3-3810 |
Related Weaknesses (CWE)
References
- http://forum.synology.com/enu/viewtopic.php?f=173&t=77644
- http://www.kb.cert.org/vuls/id/534284US Government Resource
- http://forum.synology.com/enu/viewtopic.php?f=173&t=77644
- http://www.kb.cert.org/vuls/id/534284US Government Resource
FAQ
What is CVE-2014-2264?
CVE-2014-2264 is a vulnerability with a CVSS score of 7.8 (HIGH). The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
How severe is CVE-2014-2264?
CVE-2014-2264 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2264?
Check the references section above for vendor advisories and patch information. Affected products include: Synology Diskstation Manager.