HTTP: Synology DiskStation Manager User Enumeration
This signature detects attempts to exploit a known vulnerability against Synology DiskStation Manager. A successful attack can lead to User Enumeration.
Extended Description
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
Affected Products
Synology diskstation_manager
References
CVE: CVE-2017-9554
URL: https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSM
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3
Synology
5.0