CVE-2017-9552

UnknownEPSS 0.31%

Last modified

CVE-2017-9552 is a vulnerability of currently unknown severity. A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

Metrics

EPSS Probability
0.31%

22.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SynologyPhoto Station6.0-2528
SynologyPhoto Station6.0-2636
SynologyPhoto Station6.0-2638
SynologyPhoto Station6.0-2639
SynologyPhoto Station6.0-2640
SynologyPhoto Station6.3-2944
SynologyPhoto Station6.3-2958
SynologyPhoto Station6.3-2960
SynologyPhoto Station6.3-2962
SynologyPhoto Station6.3-2963
SynologyPhoto Station6.3-2964
SynologyPhoto Station6.3-2965
SynologyPhoto Station6.4-3166
SynologyPhoto Station6.5.0-3218
SynologyPhoto Station6.5.1-3223
SynologyPhoto Station6.5.2-3225
SynologyPhoto Station6.5.3-3226
SynologyPhoto Station6.6.0-3339
SynologyPhoto Station6.6.1-3345
SynologyPhoto Station6.6.1-3346
SynologyPhoto Station6.6.2-3346
SynologyPhoto Station6.6.3-3347
SynologyPhoto Station6.7.0-3414
SynologyPhoto Station6.7.1-3419

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-9552?
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
How severe is CVE-2017-9552?
Severity scoring for CVE-2017-9552 is pending analysis. The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9552?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-9552?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST