HTTP: Synology DiskStation Manager User Enumeration
This signature detects attempts to exploit a known vulnerability against Synology DiskStation Manager. A successful attack can lead to User Enumeration.
Extended Description
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
Affected Products
Synology diskstation_manager
References
CVE: CVE-2017-9554
URL: https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSM
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Synology
5.0