CVE-2020-27648
29.10.2020, 09:15
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Enginsight
Vendor | Product | Version |
---|---|---|
synology | diskstation_manager | 6.2 ≤ 𝑥 < 6.2.3-25426-2 |
synology | skynas_firmware | 𝑥 < 6.2.3-25426 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration