#VU27678 CRLF injection in Synology SRM - CVE-2019-11823

 

#VU27678 CRLF injection in Synology SRM - CVE-2019-11823

Published: May 11, 2020


Vulnerability identifier: #VU27678
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2019-11823
CWE-ID: CWE-93
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Synology SRM
Software vendor:
Synology Inc.

Description

The vulnerability allows a remote attacker to perform CRLF injection attacks.

The vulnerability exists due to insufficient filtration of user-supplied data in the DHCP monitor's hostname parsing functionality. A remote attacker on the local network can send a specially crafted network request, trigger an out-of-bounds read and cause a denial of service (DoS) condition on the target system.

Note: This vulnerability affects the following versions:

  • Synology SRM 1.2.3 MR2200ac 8017
  • Synology SRM 1.2.3 RT2600ac 8017


Remediation

Install update from vendor's website.

External links