The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of DSM

computer threat alert CVE-2018-13284 CVE-2018-13286

Synology DSM: privilege escalation

Synthesis of the vulnerability

An attacker can bypass restrictions of Synology DSM, in order to escalate his privileges.
Severity: 2/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 25/06/2018.
Identifiers: CVE-2018-13284, CVE-2018-13286, Synology-SA-18:33, VIGILANCE-VUL-26529.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions of Synology DSM, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-10853

Linux kernel: privilege escalation via kvm/emulate.c

Synthesis of the vulnerability

An attacker can bypass restrictions via kvm/emulate.c of the Linux kernel, in order to escalate his privileges.
Severity: 2/4.
Creation date: 15/06/2018.
Identifiers: 1103505, CERTFR-2018-AVI-415, CERTFR-2018-AVI-460, CERTFR-2018-AVI-462, CERTFR-2018-AVI-480, CERTFR-2018-AVI-508, CERTFR-2019-AVI-188, CVE-2018-10853, DLA-1422-1, DLA-1422-2, DLA-1423-1, DLA-1424-1, DLA-1434-1, FEDORA-2018-f1b818a5c9, openSUSE-SU-2018:2407-1, openSUSE-SU-2019:1407-1, RHSA-2019:2029-01, RHSA-2019:2043-01, SUSE-SU-2018:2538-1, SUSE-SU-2018:2539-1, SUSE-SU-2018:2908-1, SUSE-SU-2018:2908-2, SUSE-SU-2018:3083-1, SUSE-SU-2018:3084-1, SUSE-SU-2019:1245-1, USN-3777-1, USN-3777-2, USN-3777-3, VIGILANCE-VUL-26434.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions via kvm/emulate.c of the Linux kernel, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

cybersecurity vulnerability CVE-2018-3665

Intel Microprocessors: information disclosure via Lazy FP State Restore

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via Lazy FP State Restore of Intel Microprocessors, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 14/06/2018.
Identifiers: ADV180016, CERTFR-2018-AVI-290, CERTFR-2018-AVI-292, CERTFR-2018-AVI-295, CERTFR-2018-AVI-296, CERTFR-2018-AVI-299, CERTFR-2018-AVI-301, CERTFR-2018-AVI-308, CERTFR-2018-AVI-312, CERTFR-2018-AVI-319, CERTFR-2018-AVI-321, CERTFR-2018-AVI-330, CERTFR-2018-AVI-584, CTX235745, CVE-2018-3665, DLA-1422-1, DLA-1422-2, DSA-4232-1, FEDORA-2018-d3cb6f113c, FG-IR-18-002, FreeBSD-SA-18:07.lazyfpu, HT208937, ibm10742755, INTEL-SA-00145, JSA10917, K21344224, openSUSE-SU-2018:1773-1, openSUSE-SU-2018:2116-1, openSUSE-SU-2018:2211-1, RHSA-2018:1852-01, RHSA-2018:1944-01, RHSA-2018:2164-01, RHSA-2018:2165-01, RHSA-2019:1170-01, RHSA-2019:1190-01, SUSE-SU-2018:1761-1, SUSE-SU-2018:1762-1, SUSE-SU-2018:1772-1, SUSE-SU-2018:1816-1, SUSE-SU-2018:1821-1, SUSE-SU-2018:1846-1, SUSE-SU-2018:1849-1, SUSE-SU-2018:1855-1, SUSE-SU-2018:1981-1, SUSE-SU-2018:2037-1, SUSE-SU-2018:2056-1, SUSE-SU-2018:2059-1, SUSE-SU-2018:2069-1, SUSE-SU-2018:2081-1, SUSE-SU-2018:2528-1, Synology-SA-18:31, USN-3696-1, USN-3696-2, USN-3698-1, USN-3698-2, VIGILANCE-VUL-26423, XSA-267.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via Lazy FP State Restore of Intel Microprocessors, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

weakness CVE-2018-0732

OpenSSL: denial of service via Large DH Parameter

Synthesis of the vulnerability

An attacker can generate a fatal error via Large DH Parameter of OpenSSL, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 12/06/2018.
Identifiers: bulletinjul2018, CERTFR-2018-AVI-511, CERTFR-2018-AVI-607, cpuapr2019, cpujan2019, cpujul2019, cpuoct2018, CVE-2018-0732, DLA-1449-1, DSA-4348-1, DSA-4355-1, FEDORA-2019-00c25b9379, ibm10719319, ibm10729805, ibm10738401, ibm10743283, ibm10874728, JSA10919, K21665601, openSUSE-SU-2018:1906-1, openSUSE-SU-2018:2117-1, openSUSE-SU-2018:2129-1, openSUSE-SU-2018:2667-1, openSUSE-SU-2018:2695-1, openSUSE-SU-2018:2816-1, openSUSE-SU-2018:2855-1, openSUSE-SU-2018:3013-1, openSUSE-SU-2018:3015-1, PAN-SA-2018-0015, RHSA-2018:3221-01, SSA:2018-226-01, SUSE-SU-2018:1887-1, SUSE-SU-2018:1968-1, SUSE-SU-2018:2036-1, SUSE-SU-2018:2041-1, SUSE-SU-2018:2207-1, SUSE-SU-2018:2647-1, SUSE-SU-2018:2683-1, SUSE-SU-2018:2812-1, SUSE-SU-2018:2956-1, SUSE-SU-2018:2965-1, SUSE-SU-2019:1553-1, SYMSA1462, TNS-2018-14, TNS-2018-17, TSB17568, USN-3692-1, USN-3692-2, VIGILANCE-VUL-26375.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a fatal error via Large DH Parameter of OpenSSL, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer threat bulletin CVE-2018-13283

Synology DSM SSL VPN Client: Man-in-the-Middle

Synthesis of the vulnerability

An attacker can act as a Man-in-the-Middle on Synology DSM SSL VPN Client, in order to read or write data in the session.
Severity: 2/4.
Creation date: 01/06/2018.
Identifiers: CVE-2018-13283, Synology-SA-18:30, VIGILANCE-VUL-26298.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can act as a Man-in-the-Middle on Synology DSM SSL VPN Client, in order to read or write data in the session.
Full Vigil@nce bulletin... (Free trial)

security announce CVE-2018-8913

Synology DSM Web Station: information disclosure via Phishing

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via Phishing of Synology DSM Web Station, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 01/06/2018.
Identifiers: CVE-2018-8913, Synology-SA-18:29, VIGILANCE-VUL-26297.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via Phishing of Synology DSM Web Station, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

cybersecurity alert CVE-2017-16775

Synology DSM: privilege escalation via SSO Server

Synthesis of the vulnerability

An attacker can bypass restrictions via SSO Server of Synology DSM, in order to escalate his privileges.
Severity: 2/4.
Creation date: 31/05/2018.
Identifiers: CVE-2017-16775, Synology-SA-18:28, VIGILANCE-VUL-26284.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions via SSO Server of Synology DSM, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

cybersecurity note 26283

Synology DSM: privilege escalation via Universal Search

Synthesis of the vulnerability

An attacker can bypass restrictions via Universal Search of Synology DSM, in order to escalate his privileges.
Severity: 2/4.
Creation date: 31/05/2018.
Identifiers: Synology-SA-18:27, VIGILANCE-VUL-26283.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass restrictions via Universal Search of Synology DSM, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

weakness bulletin CVE-2017-16774

Synology DSM: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Synology DSM, in order to run JavaScript code in the context of the web site.
Severity: 2/4.
Creation date: 31/05/2018.
Identifiers: CVE-2017-16774, Synology-SA-18:26, VIGILANCE-VUL-26282.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

The Synology DSM product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Synology DSM, in order to run JavaScript code in the context of the web site.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2017-12075 CVE-2018-8916

Synology DiskStation Manager: multiple vulnerabilities

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Synology DiskStation Manager.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 23/05/2018.
Identifiers: CVE-2017-12075, CVE-2018-8916, Synology-SA-18:24, VIGILANCE-VUL-26206.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Synology DiskStation Manager.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about DSM: