454
VMScore

CVE-2020-27652

Published: 29/10/2020 Updated: 16/11/2022
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 8.3 | Impact Score: 6 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) prior to 6.2.3-25426-2 allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synology diskstation manager

synology skynas_firmware

Github Repositories

Synology NAS file management from command-line

Synology NAS file management from command-line synocli is a command-line tool and Python API than interacts with a DSM7 based Synology device using the Web API: download files with multiple threads and automatic resume list files provide interactive python shell to query the APIs connection in direct using ip|fqdn:port of your device connection through QuickConnect usi