CVE-2020-27648

CVSS 3.1 Score 9 of 10 (high)

Details

Published Oct 29, 2020
Updated: Jan 14, 2025
CWE ID 295

Summary

CVE-2020-27648 is a vulnerability affecting OpenVPN clients in Synology DiskStation Manager (DSM) prior to version 6.2.3-25426-2. This issue involves improper certificate validation, enabling man-in-the-middle attackers to spoof servers and intercept sensitive information by providing crafted certificates. Successful exploitation of this vulnerability could lead to unauthorized access to data transmitted over the affected OpenVPN connections. Users are urged to update their Synology DSM installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology