Lucene search

K
cvelistCertccCVELIST:CVE-2016-6554
HistoryJul 13, 2018 - 8:00 p.m.

CVE-2016-6554 Synology NAS servers DS107, DS116, and DS213, use default credentials

2018-07-1320:00:00
CWE-255
certcc
www.cve.org

9.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.

CNA Affected

[
  {
    "product": "NAS server DS107",
    "vendor": "Synology",
    "versions": [
      {
        "lessThanOrEqual": "3.1-1639",
        "status": "affected",
        "version": "3.1-1639",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "NAS server DS116",
    "vendor": "Synology",
    "versions": [
      {
        "lessThan": "5.2-5644-1",
        "status": "affected",
        "version": "5.2-5644-1",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "NAS server DS213",
    "vendor": "Synology",
    "versions": [
      {
        "lessThan": "5.2-5644-1",
        "status": "affected",
        "version": "5.2-5644-1",
        "versionType": "custom"
      }
    ]
  }
]

9.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

Related for CVELIST:CVE-2016-6554