nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9554 CVE-2017-9554
MEDIUM
synology diskstation_manager Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2017-9554 has a selected CVSS score of 5.3 (medium); EIP currently links 2 catalogued exploits and 2 repository PoCs.
Description
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
diskstation_managerBrowse synology / diskstation_manager | VulnCheck | Version data not supplied | |
Proofs of concept
4Catalogued exploits
ExploitDBSynology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User EnumerationExploitDB exploitby Steve KaunNot analyzed1 file
MetasploitSynology Forget Password User Enumeration ScannerMetasploit auxiliary PoCby Steve Kaun +1 moreNot analyzed1 file
Repository PoCs
GitHubrfcl/Synology-DiskStation-User-Enumeration-CVE-2017-9554-Repository PoCby rfclStars: 2Not analyzed2 files
GitHubEz0-yf/CVE-2017-9554-Exploit-ToolRepository PoCby Ez0-yfStars: 0Not analyzed8 files
References
343455exploit
https://www.exploit-db.com/exploits/43455 synology.comConfirmation
https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSM