CVE-2020-27652

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Oct 29, 2020
Updated: Jan 14, 2025
CWE ID 327

Summary

CVE-2020-27652 is an algorithm downgrade vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2.3-25426-2. This issue allows man-in-the-middle attackers to spoof servers and extract sensitive information through unspecified vectors. By intercepting communications and manipulating the encryption algorithm, an adversary can gain unauthorized access to data, potentially leading to significant security breaches. This vulnerability underscores the importance of timely software updates and encryption best practices to secure Synology DSM installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology