CVE-2023-52950
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 2, 2024
CWE ID 311
Summary
CVE-2023-52950 is a new vulnerability affecting Synology Active Backup for Business Agent before version 2.7.0-3221. This issue involves a missing encryption feature in the login component, making user credentials susceptible to interception. Adjacent man-in-the-middle attackers can exploit this unspecified vulnerability and gain access to sensitive user information, posing a significant risk to data security. Organizations using the Synology Active Backup for Business Agent are encouraged to upgrade to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Synology Active Backup for Business Agent
Affected Vendors
- Synology