Synology-SA-18:19 SSL VPN Client
Publish Time: 2018-04-26 15:47:29 UTC+8
Last Updated: 2018-07-06 10:10:12 UTC+8
- Severity
- Important
- Status
- Resolved
Abstract
A vulnerability allows remote attackers to conduct man-in-the-middle attacks to a susceptible version of SSL VPN Client.
Affected Products
Product | Severity | Fixed Release Availability |
---|---|---|
SSL VPN Client[1] | Important | Upgrade to 1.2.4-0224 or above. |
[1] A vulnerability allows remote attackers to conduct man-in-the-middle attacks to a susceptible version of SSL VPN Client.
Mitigation
None
Detail
- CVE-2018-8929
- Severity: Important
- CVSS3 Base Score: 7.3
- CVSS3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
Acknowledgement
丁諭祺(Yu-Chi Ding) from DEVCORE CHROOT
Revision
Revision | Date | Description |
---|---|---|
1 | 2018-04-26 | Initial public release. |
2 | 2018-07-06 | Disclosed vulnerability details. |