CVE-2023-52951 PUBLISHED

Assigner: synology
Reserved: 24.09.2024 Published: 03.06.2026 Updated: 03.06.2026

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor Synology
Product Synology Note Station Client
Versions Default: affected
  • affected from * to 2.2.4-703 (excl.)

Credits

  • Zhao Runzi (赵润梓) finder

References

Problem Types

  • Cleartext Transmission of Sensitive Information CWE