← Back

CVE-2010-3684

nvd nist
Published: Sep 29, 2010Modified: Apr 29, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.

Affected (9)

Products: Synology: Dsm
1 product
Dsm
Configuration A
9 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Synology
Version 2.2-0942
Version 2.2-1041
Version 2.2-1042
Version 2.2-1045
Version 2.3-1139
Version 2.3-1141
Version 2.3-1144
Version 2.3-1157
Version 2.3-1161
Running on/withPlatform Versions
Synology
Disk Station Ds1010+
All versions
Synology
Disk Station Ds109
All versions
Synology
Disk Station Ds110+
All versions
Synology
Disk Station Ds110j
All versions
Synology
Disk Station Ds209
All versions
Synology
Disk Station Ds210+
All versions
Synology
Disk Station Ds210j
All versions
Synology
Disk Station Ds409slim
All versions
Synology
Disk Station Ds410
All versions
Synology
Disk Station Ds410j
All versions
Synology
Disk Station Ds411+
All versions
Synology
Disk Station Ds710+
All versions

Related CWEs

Timeline

No history available yet.