Vulnerability Description
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Diskstation Manager | <= 6.1.1-15101-4 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/43455/
- https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSMMitigationVendor Advisory
- https://www.exploit-db.com/exploits/43455/
- https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSMMitigationVendor Advisory
FAQ
What is CVE-2017-9554?
CVE-2017-9554 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
How severe is CVE-2017-9554?
CVE-2017-9554 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9554?
Check the references section above for vendor advisories and patch information. Affected products include: Synology Diskstation Manager.