CVE-2020-27653

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Oct 29, 2020
Updated: Jan 14, 2025
CWE ID 327

Summary

CVE-2020-27653 is a vulnerability affecting Synology Router Manager (SRM) versions prior to 1.2.4-8081. This issue allows man-in-the-middle attackers to manipulate the QuickConnect algorithm, enabling them to pose as servers and extract sensitive information through unspecified means. The algorithm downgrade vulnerability exposes users to potential data breaches, emphasizing the importance of updating to the latest version of SRM to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Synology Router Manager
  • DiskStation Manager

Affected Vendors

  • Synology