CVE-2020-27650
Summary
| CVE | CVE-2020-27650 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-29 09:15:00 UTC |
| Updated | 2020-11-05 18:21:00 UTC |
| Description | Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Diskstation Manager | All | All | All | All |
| Application | Synology | Diskstation Manager | All | All | All | All |
| Hardware | Synology | Skynas | - | All | All | All |
| Hardware | Synology | Skynas | - | All | All | All |
| Operating System | Synology | Skynas Firmware | All | All | All | All |
| Operating System | Synology | Skynas Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Synology Inc. | CONFIRM | www.synology.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.