CVE-2023-52950

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 2, 2024
CWE ID 311

Summary

CVE-2023-52950 is a new vulnerability affecting Synology Active Backup for Business Agent before version 2.7.0-3221. This issue involves a missing encryption feature in the login component, making user credentials susceptible to interception. Adjacent man-in-the-middle attackers can exploit this unspecified vulnerability and gain access to sensitive user information, posing a significant risk to data security. Organizations using the Synology Active Backup for Business Agent are encouraged to upgrade to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Synology Active Backup for Business Agent

Affected Vendors

  • Synology