CVE-2023-2729

Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
synologyCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
synologydiskstation_manager_unified_controller
3.1
synologyrouter_manager
1.2 ≤
𝑥
< 1.3.1-9346
synologyrouter_manager
1.3.1-9346
synologyrouter_manager
1.3.1-9346:update_1
synologyrouter_manager
1.3.1-9346:update_2
synologyrouter_manager
1.3.1-9346:update_3
synologyrouter_manager
1.3.1-9346:update_4
synologyrouter_manager
1.3.1-9346:update_5
synologydiskstation_manager
6.2 ≤
𝑥
< 7.2-64561
𝑥
= Vulnerable software versions