CVE-2018-13280
CVSS 3.0 Score 5.9 of 10 (medium)
Details
Summary
CVE-2018-13280 is a vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2-23739. The issue lies in the SYNO.Encryption.GenRandomKey function, which generates insufficiently random values. An attacker can exploit this weakness during man-in-the-middle attacks, compromising non-HTTPS sessions without the need for HTTPS certificate weaknesses. The precise attack vectors are unspecified, but the impact could lead to sensitive data exposure or unauthorized access. Users are strongly advised to update their DSM instances to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology