CVE Vulnerabilities

CVE-2017-9552

Improper Authentication

Published: Jun 13, 2017 | Modified: Oct 09, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by synophoto_dsm_user –auth USERNAME PASSWORD, and local users are able to obtain credentials by sniffing /proc/*/cmdline.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Photo_station Synology 6.0-2528 (including) 6.0-2528 (including)
Photo_station Synology 6.0-2636 (including) 6.0-2636 (including)
Photo_station Synology 6.0-2638 (including) 6.0-2638 (including)
Photo_station Synology 6.0-2639 (including) 6.0-2639 (including)
Photo_station Synology 6.0-2640 (including) 6.0-2640 (including)
Photo_station Synology 6.3-2944 (including) 6.3-2944 (including)
Photo_station Synology 6.3-2958 (including) 6.3-2958 (including)
Photo_station Synology 6.3-2960 (including) 6.3-2960 (including)
Photo_station Synology 6.3-2962 (including) 6.3-2962 (including)
Photo_station Synology 6.3-2963 (including) 6.3-2963 (including)
Photo_station Synology 6.3-2964 (including) 6.3-2964 (including)
Photo_station Synology 6.3-2965 (including) 6.3-2965 (including)
Photo_station Synology 6.4-3166 (including) 6.4-3166 (including)
Photo_station Synology 6.5.0-3218 (including) 6.5.0-3218 (including)
Photo_station Synology 6.5.1-3223 (including) 6.5.1-3223 (including)
Photo_station Synology 6.5.2-3225 (including) 6.5.2-3225 (including)
Photo_station Synology 6.5.3-3226 (including) 6.5.3-3226 (including)
Photo_station Synology 6.6.0-3339 (including) 6.6.0-3339 (including)
Photo_station Synology 6.6.1-3345 (including) 6.6.1-3345 (including)
Photo_station Synology 6.6.1-3346 (including) 6.6.1-3346 (including)
Photo_station Synology 6.6.2-3346 (including) 6.6.2-3346 (including)
Photo_station Synology 6.6.3-3347 (including) 6.6.3-3347 (including)
Photo_station Synology 6.7.0-3414 (including) 6.7.0-3414 (including)
Photo_station Synology 6.7.1-3419 (including) 6.7.1-3419 (including)

Potential Mitigations

References