Overview
Synology DiskStation Manager VPN module contains a hard-coded password which cannot be changed.
Description
Synology DiskStation Manager 4.3-3810 update 1 and possibly earlier versions contain a VPN server module which contains a hard-coded password which cannot be changed. According to the original forum post: |
Impact
A remote unauthenticated attacker may be able to connect to the Synology DiskStation Manager using the VPN server and access the Synology device and other devices on the shared network. |
Solution
Update
|
Disable OpenVPN module
|
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 7.8 | AV:N/AC:L/Au:N/C:C/I:N/A:N |
| Temporal | 7 | E:F/RL:W/RC:C |
| Environmental | 2.0 | CDP:LM/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
This vulnerability was originally posted by tesla563, and thanks to Radovan Haban for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | None |
| Date Public: | 2013-12-01 |
| Date First Published: | 2014-02-27 |
| Date Last Updated: | 2014-03-04 12:39 UTC |
| Document Revision: | 14 |