#VU52348 Cleartext transmission of sensitive information in DiskStation Manager (DSM) - CVE-2021-26560
Published: April 20, 2021
DiskStation Manager (DSM)
Synology Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information within the synoagentregisterd server finder functionality. A remote attacker can perform a man-in-the-middle attack and gain access to sensitive data.