CVE-2018-13286

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2019
Last modified:
14/01/2025

Description

Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 5.2 (including) 5.2-5967-8 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.0 (including) 6.0.3-8754-8 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.1 (including) 6.1.7-15284-1 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.2 (including) 6.2-23739-1 (excluding)