|
209581
|
10.0 |
CRITICAL
Network
|
synology
|
router_manager
|
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
|
CWE-269
Improper Privilege Management
|
CVE-2020-27655
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209582
|
9.8 |
CRITICAL
Network
|
synology
|
router_manager
|
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
|
CWE-269
Improper Privilege Management
|
CVE-2020-27654
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209583
|
8.3 |
HIGH
Network
|
synology
|
router_manager diskstation_manager
|
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecifi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-27653
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209584
|
8.3 |
HIGH
Network
|
synology
|
diskstation_manager skynas_firmware
|
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via u…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-27652
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209585
|
8.1 |
HIGH
Network
|
synology
|
router_manager
|
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercept…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-27651
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209586
|
3.7 |
LOW
Network
|
synology
|
diskstation_manager skynas_firmware
|
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by i…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-27650
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209587
|
9.0 |
CRITICAL
Network
|
synology
|
router_manager
|
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-27649
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209588
|
9.0 |
CRITICAL
Network
|
synology
|
diskstation_manager skynas_firmware
|
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive inf…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-27648
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209589
|
6.5 |
MEDIUM
Network
|
citadel
|
webcit
|
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was r…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-27742
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209590
|
6.1 |
MEDIUM
Network
|
citadel
|
webcit
|
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. NOTE: this was repor…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27741
|
2024-11-21 14:21 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|