PT-2018-18714 · Synology · Synology Diskstation Manager

CVE-2018-8916

·

Publicado

2018-06-08

·

Atualizado

2025-01-14

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 6.2-23739
Description The issue concerns an unverified password change vulnerability in the Change Password feature. This allows remote authenticated users to reset passwords without proper verification.
Recommendations For versions prior to 6.2-23739, update to version 6.2-23739 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8916

Produtos afetados

Synology Diskstation Manager