CVE-2020-27650
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD
Description
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
Affected (2)
Products: Synology: Diskstation Manager, Skynas Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.2 to 6.2.3-25426-2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.2.3-25426 |
| Running on/with | Platform Versions |
|---|---|
Synology Skynas | All versions |
Related CWEs
CWE-311
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.
References (2)
Source: security@synology.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.