The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
References
Link | Resource |
---|---|
http://forum.synology.com/enu/viewtopic.php?f=173&t=77644 | |
http://www.kb.cert.org/vuls/id/534284 | US Government Resource |
Configurations
Information
Published : 2014-03-02 09:55
Updated : 2014-03-03 12:47
NVD link : CVE-2014-2264
Mitre link : CVE-2014-2264
JSON object : View
CWE
Products Affected
synology
- diskstation_manager