Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Diskstation_manager | Synology | 7.1 (including) | 7.1.1-42962-8 (excluding) |
| Diskstation_manager | Synology | 7.2.1-69057 (including) | 7.2.1-69057-7 (excluding) |
| Diskstation_manager | Synology | 7.2.2 (including) | 7.2.2-72806-3 (excluding) |