CVE-2021-26560

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Feb 26, 2021
Updated: Jan 14, 2025
CWE ID 319

Summary

CVE-2021-26560 is a cleartext transmission vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue allows man-in-the-middle attackers to spoof servers and intercept sensitive information during an HTTP session due to the unencrypted transmission of data. The vulnerability poses a significant risk as it enables unauthorized access to confidential data, increasing the likelihood of data breaches or unauthorized modifications. It is crucial for Synology users to update their DSM to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology