CVE-2017-9552

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
synologyCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
synologyphoto_station
6.0-2528
synologyphoto_station
6.0-2636
synologyphoto_station
6.0-2638
synologyphoto_station
6.0-2639
synologyphoto_station
6.0-2640
synologyphoto_station
6.3-2944
synologyphoto_station
6.3-2958
synologyphoto_station
6.3-2960
synologyphoto_station
6.3-2962
synologyphoto_station
6.3-2963
synologyphoto_station
6.3-2964
synologyphoto_station
6.3-2965
synologyphoto_station
6.4-3166
synologyphoto_station
6.5.0-3218
synologyphoto_station
6.5.1-3223
synologyphoto_station
6.5.2-3225
synologyphoto_station
6.5.3-3226
synologyphoto_station
6.6.0-3339
synologyphoto_station
6.6.1-3345
synologyphoto_station
6.6.1-3346
synologyphoto_station
6.6.2-3346
synologyphoto_station
6.6.3-3347
synologyphoto_station
6.7.0-3414
synologyphoto_station
6.7.1-3419
𝑥
= Vulnerable software versions