PT-2010-4998 · Synology · Synology Disk Station
Publicado
2010-09-29
·
Atualizado
2018-10-10
·
CVE-2010-3684
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Synology Disk Station versions 2.x
Description
The FTP authentication module logs passwords to the web application interface in cases of incorrect login attempts, allowing local users to obtain sensitive information by reading a log.
Recommendations
For Synology Disk Station versions 2.x, consider disabling the FTP authentication module until a patch is available to prevent local users from obtaining sensitive information. Restrict access to the log files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Synology Disk Station