CVE-2017-9553

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Jul 24, 2017
Updated: Jan 14, 2025

Summary

CVE-2017-9553 is a design flaw affecting Synology DiskStation Manager (DSM) before version 6.1.3-15152. The vulnerability resides in SYNO.API.Encryption, allowing remote attackers to bypass the encryption protection mechanism through a specially crafted version parameter. This issue poses a significant risk as it enables unauthorized access to data that is supposed to be encrypted, potentially leading to data theft or unintended exposure. Synology strongly advises users to upgrade their DSM to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology