← Back

CVE-2020-27650

nvd nist
Published: Oct 29, 2020Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

Affected (2)

2 products
Diskstation Manager
Skynas Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.2 to 6.2.3-25426-2
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.2.3-25426
Running on/withPlatform Versions
Synology
Skynas
All versions

References (2)

Source: security@synology.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.