CVE-2020-27648
CVSS 3.1 Score 9 of 10 (high)
Details
Published Oct 29, 2020
Updated: Jan 14, 2025
CWE ID 295
Summary
CVE-2020-27648 is a vulnerability affecting OpenVPN clients in Synology DiskStation Manager (DSM) prior to version 6.2.3-25426-2. This issue involves improper certificate validation, enabling man-in-the-middle attackers to spoof servers and intercept sensitive information by providing crafted certificates. Successful exploitation of this vulnerability could lead to unauthorized access to data transmitted over the affected OpenVPN connections. Users are urged to update their Synology DSM installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology