CVE-2020-27650
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
CVE-2020-27650 is a vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2.3-25426-2. This issue allows remote attackers to intercept session cookies during HTTP transmissions, as DSM fails to set the Secure flag for these cookies in HTTPS sessions. Consequently, confidential data exchanged between the user and the DSM could be exposed. Attackers could potentially use this vulnerability to gain unauthorized access to user accounts, leading to potential data theft or system compromise. It is highly recommended for Synology users to upgrade their DSM systems to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology