CVE-2020-27650

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Oct 29, 2020
Updated: Jan 14, 2025
CWE ID 311
CWE ID 614

Summary

CVE-2020-27650 is a vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2.3-25426-2. This issue allows remote attackers to intercept session cookies during HTTP transmissions, as DSM fails to set the Secure flag for these cookies in HTTPS sessions. Consequently, confidential data exchanged between the user and the DSM could be exposed. Attackers could potentially use this vulnerability to gain unauthorized access to user accounts, leading to potential data theft or system compromise. It is highly recommended for Synology users to upgrade their DSM systems to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology