Impact
An improper restriction of excessive authentication attempts in the Auto Block feature of Synology DiskStation Manager allows remote attackers to repeatedly attempt to authenticate and then read a restricted set of files. The flaw does not permit arbitrary code execution; it is limited to reading files whose paths can be enumerated through successful brute‑force attempts. This information disclosure can compromise sensitive data stored on the device.
Affected Systems
Synology DiskStation Manager (DSM) versions earlier than 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are affected. The vulnerability exists in DSM releases prior to these revision numbers; newer releases incorporate the fix.
Risk and Exploitability
The CVSS score of 3.7 classifies this issue as low severity, and the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this weakness remotely over the network by launching brute‑force login attempts against the DSM Auto Block feature. Successful brute‑force attempts enable enumeration and reading of a small set of files, potentially revealing confidential information, but the impact is constrained by the limited file set.
OpenCVE Enrichment