vendor:
DiskStation Manager (DSM)
by:
Steve Kaun
5.3
CVSS
MEDIUM
User Enumeration
200
CWE
Product Name: DiskStation Manager (DSM)
Affected Version From: Before 6.1.3-15152
Affected Version To: 6.1.3-15152
Patch Exists: YES
Related CWE: CVE-2017-9554
CPE: a:synology:diskstation_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors. This can be done by sending a request to the forget_passwd.cgi page with a username as a parameter.
Mitigation:
Upgrade to the latest version of Synology DiskStation Manager (DSM) 6.1.3-15152 or later.