9.8
CVE-2026-13639
- EPSS 0.51%
- Veröffentlicht 18.09.2026 08:21:27
- Zuletzt bearbeitet 18.09.2026 20:17:06
- Erkennungen
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSynology
≫
Produkt
DiskStation Manager (DSM)
Default Statusaffected
Version
7.4
Version <
7.4-90075
Status
affected
Version
7.3.2
Version <
7.3.2-86009-4
Status
affected
Version
7.2.2
Version <
7.2.2-72806-9
Status
affected
Version
7.2.1
Version <
7.2.1-69057-12
Status
affected
Version
0
Version <
7.2.1
Status
unknown
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.422 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Synology | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-331 Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13