CVE-2018-13280

CVSS 3.0 Score 5.9 of 10 (medium)

Details

Published Jul 30, 2018
Updated: Jan 14, 2025
CWE ID 330

Summary

CVE-2018-13280 is a vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2-23739. The issue lies in the SYNO.Encryption.GenRandomKey function, which generates insufficiently random values. An attacker can exploit this weakness during man-in-the-middle attacks, compromising non-HTTPS sessions without the need for HTTPS certificate weaknesses. The precise attack vectors are unspecified, but the impact could lead to sensitive data exposure or unauthorized access. Users are strongly advised to update their DSM instances to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology