RnD Research Lab

Cyber Security => IT News => Topic started by: ixsky on

Title: New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager
Post by: ixsky on
New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager

A medium-severity flaw has been discovered in Synology's DiskStation Manager (DSM) that could be exploited to decipher an administrator's password and remotely hijack the account.
"Under some rare conditions, an attacker could leak enough information to restore the seed of the pseudorandom number generator (PRNG), reconstruct the admin password, and remotely take over the admin account,"

Source: New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager (https://thehackernews.com/2023/10/new-admin-takeover-vulnerability.html)