Record summary

CVE-2017-9554 has a selected CVSS score of 5.3 (medium); EIP currently links 2 catalogued exploits and 2 repository PoCs.

Description

An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 23, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
2
Repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

4

Catalogued exploits

ExploitDBSynology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User EnumerationExploitDB exploitby Steve KaunNot analyzed1 file
ExploitDB

PoC details
MetasploitSynology Forget Password User Enumeration ScannerMetasploit auxiliary PoCby Steve Kaun +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Repository PoCs

GitHubrfcl/Synology-DiskStation-User-Enumeration-CVE-2017-9554-Repository PoCby rfclStars: 2Not analyzed2 files

1.3 KiB

GitHub

PoC details
GitHubEz0-yf/CVE-2017-9554-Exploit-ToolRepository PoCby Ez0-yfStars: 0Not analyzed8 files

815.6 KiB

GitHub

PoC details

References

3