CVE-2018-13291

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
01/04/2019
Last modified:
14/01/2025

Description

Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 5.2 (including) 6.2.1-23824 (excluding)