Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-9552

Опубликовано: 13 июн. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 2.1
EPSS Низкий

Описание

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:synology:photo_station:6.0-2528:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.0-2636:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.0-2638:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.0-2639:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.0-2640:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2944:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2958:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2960:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2962:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2963:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2964:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.3-2965:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.4-3166:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.5.0-3218:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.5.1-3223:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.5.2-3225:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.5.3-3226:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.6.0-3339:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.6.1-3345:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.6.1-3346:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.6.2-3346:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.6.3-3347:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.7.0-3414:*:*:*:*:*:*:*
cpe:2.3:a:synology:photo_station:6.7.1-3419:*:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00044
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-522
CWE-287

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

EPSS

Процентиль: 13%
0.00044
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-522
CWE-287