The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Synology
Subscribe
|
Disk Station Ds1010\+
Subscribe
Disk Station Ds109
Subscribe
Disk Station Ds110\+
Subscribe
Disk Station Ds110j
Subscribe
Disk Station Ds209
Subscribe
Disk Station Ds210\+
Subscribe
Disk Station Ds210j
Subscribe
Disk Station Ds409slim
Subscribe
Disk Station Ds410
Subscribe
Disk Station Ds410j
Subscribe
Disk Station Ds411\+
Subscribe
Disk Station Ds710\+
Subscribe
Dsm
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-3668 | The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://www.securityfocus.com/archive/1/513970/100/0/threaded |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T03:18:52.943Z
Reserved: 2010-09-29T00:00:00
Link: CVE-2010-3684
No data.
Status : Deferred
Published: 2010-09-29T17:00:05.743
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3684
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD