PT-2022-18524 · Synology · Synology Note Station Client

Cq674350529

+1

·

Published

2022-08-03

·

Updated

2022-08-09

·

CVE-2022-27619

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Note Station Client versions prior to 2.2.2-609
Description The issue concerns a cleartext transmission of sensitive information vulnerability in authentication management. This allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Recommendations For versions prior to 2.2.2-609, update to version 2.2.2-609 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and minimizing the use of unsecured connections until the update is applied.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-27619

Affected Products

Synology Note Station Client