Vulnerability Name:

CVE-2017-9552 (CCN-127202)

Assigned:2017-06-09
Published:2017-06-09
Updated:2019-10-09
Summary:A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Obtain Information
References:Source: MISC
Type: Issue Tracking, Third Party Advisory
http://blog.crozat.net/2017/06/synology-photostation-password-vulnerabilty.html

Source: MITRE
Type: CNA
CVE-2017-9552

Source: XF
Type: UNKNOWN
synology-cve20179552-info-disc(127202)

Source: CCN
Type: Synology Web site
CVE-2017-9552 has been found in Photo Station and allows local users to obtain sensitive information of other users.

Source: CONFIRM
Type: Third Party Advisory
https://www.synology.com/en-global/support/security/Photo_Station_CVE_2017_9552

Vulnerable Configuration:Configuration 1:
  • cpe:/a:synology:photo_station:6.0-2528:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.0-2636:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.0-2638:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.0-2639:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.0-2640:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2944:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2958:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2960:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2962:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2963:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2964:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.3-2965:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.4-3166:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.5.0-3218:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.5.1-3223:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.5.2-3225:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.5.3-3226:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.6.0-3339:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.6.1-3345:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.6.1-3346:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.6.2-3346:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.6.3-3347:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.7.0-3414:*:*:*:*:*:*:*
  • OR cpe:/a:synology:photo_station:6.7.1-3419:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:synology:photo_station:6.7.1-3419:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    synology photo station 6.0-2528
    synology photo station 6.0-2636
    synology photo station 6.0-2638
    synology photo station 6.0-2639
    synology photo station 6.0-2640
    synology photo station 6.3-2944
    synology photo station 6.3-2958
    synology photo station 6.3-2960
    synology photo station 6.3-2962
    synology photo station 6.3-2963
    synology photo station 6.3-2964
    synology photo station 6.3-2965
    synology photo station 6.4-3166
    synology photo station 6.5.0-3218
    synology photo station 6.5.1-3223
    synology photo station 6.5.2-3225
    synology photo station 6.5.3-3226
    synology photo station 6.6.0-3339
    synology photo station 6.6.1-3345
    synology photo station 6.6.1-3346
    synology photo station 6.6.2-3346
    synology photo station 6.6.3-3347
    synology photo station 6.7.0-3414
    synology photo station 6.7.1-3419
    synology photo station 6.7.1-3419