Show filters
300 Total Results
Displaying 141-150 of 300
Sort by:
Attacker Value
Unknown

CVE-2020-27653

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
Attacker Value
Unknown

CVE-2020-27657

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
Attacker Value
Unknown

CVE-2020-27651

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Attacker Value
Unknown

CVE-2020-27655

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
Attacker Value
Unknown

CVE-2020-27650

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Attacker Value
Unknown

CVE-2020-27658

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Attacker Value
Unknown

CVE-2020-27649

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Attacker Value
Unknown

CVE-2020-27652

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
Attacker Value
Unknown

CVE-2020-27656

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
Attacker Value
Unknown

CVE-2020-27654

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.