Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-3684


The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.


Published

2010-09-29T17:00:05.743

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.1 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System synology dsm 2.2-0942 Yes
Operating System synology dsm 2.2-1041 Yes
Operating System synology dsm 2.2-1042 Yes
Operating System synology dsm 2.2-1045 Yes
Operating System synology dsm 2.3-1139 Yes
Operating System synology dsm 2.3-1141 Yes
Operating System synology dsm 2.3-1144 Yes
Operating System synology dsm 2.3-1157 Yes
Operating System synology dsm 2.3-1161 Yes
Hardware synology disk_station_ds1010\+ * No
Hardware synology disk_station_ds109 * No
Hardware synology disk_station_ds110\+ * No
Hardware synology disk_station_ds110j * No
Hardware synology disk_station_ds209 * No
Hardware synology disk_station_ds210\+ * No
Hardware synology disk_station_ds210j * No
Hardware synology disk_station_ds409slim * No
Hardware synology disk_station_ds410 * No
Hardware synology disk_station_ds410j * No
Hardware synology disk_station_ds411\+ * No
Hardware synology disk_station_ds710\+ * No

References