Lucene search

K
nvd[email protected]NVD:CVE-2010-3684
HistorySep 29, 2010 - 5:00 p.m.

CVE-2010-3684

2010-09-2917:00:05
CWE-255
web.nvd.nist.gov

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.6%

The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.

Affected configurations

NVD
Node
synologydsmMatch2.2-0942
OR
synologydsmMatch2.2-1041
OR
synologydsmMatch2.2-1042
OR
synologydsmMatch2.2-1045
OR
synologydsmMatch2.3-1139
OR
synologydsmMatch2.3-1141
OR
synologydsmMatch2.3-1144
OR
synologydsmMatch2.3-1157
OR
synologydsmMatch2.3-1161
AND
synologydisk_station_ds1010\+
OR
synologydisk_station_ds109
OR
synologydisk_station_ds110\+
OR
synologydisk_station_ds110j
OR
synologydisk_station_ds209
OR
synologydisk_station_ds210\+
OR
synologydisk_station_ds210j
OR
synologydisk_station_ds409slim
OR
synologydisk_station_ds410
OR
synologydisk_station_ds410j
OR
synologydisk_station_ds411\+
OR
synologydisk_station_ds710\+

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.6%