Vulnerability Description
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Diskstation Manager | <= 6.1.1-15101-4 |
References
- https://www.2-sec.com/2017/06/2-secs-expert-team-uncovers-new-vulnerability-popu
- https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSMMitigationVendor Advisory
- https://www.2-sec.com/2017/06/2-secs-expert-team-uncovers-new-vulnerability-popu
- https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSMMitigationVendor Advisory
FAQ
What is CVE-2017-9553?
CVE-2017-9553 is a vulnerability with a CVSS score of 7.5 (HIGH). A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
How severe is CVE-2017-9553?
CVE-2017-9553 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9553?
Check the references section above for vendor advisories and patch information. Affected products include: Synology Diskstation Manager.