CVE-2016-6554

Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.
References
Link Resource
https://www.kb.cert.org/vuls/id/404187 Third Party Advisory US Government Resource
https://www.securityfocus.com/bid/93805 Third Party Advisory VDB Entry
https://www.synology.com/en-global/releaseNote/DS213 Release Notes Vendor Advisory
https://www.kb.cert.org/vuls/id/404187 Third Party Advisory US Government Resource
https://www.securityfocus.com/bid/93805 Third Party Advisory VDB Entry
https://www.synology.com/en-global/releaseNote/DS213 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:synology:ds107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds107:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:synology:ds213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds213:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:synology:ds116_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds116:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:56

Type Values Removed Values Added
References () https://www.kb.cert.org/vuls/id/404187 - Third Party Advisory, US Government Resource () https://www.kb.cert.org/vuls/id/404187 - Third Party Advisory, US Government Resource
References () https://www.securityfocus.com/bid/93805 - Third Party Advisory, VDB Entry () https://www.securityfocus.com/bid/93805 - Third Party Advisory, VDB Entry
References () https://www.synology.com/en-global/releaseNote/DS213 - Release Notes, Vendor Advisory () https://www.synology.com/en-global/releaseNote/DS213 - Release Notes, Vendor Advisory

Information

Published : 2018-07-13 20:29

Updated : 2024-11-21 02:56


NVD link : CVE-2016-6554

Mitre link : CVE-2016-6554

CVE.ORG link : CVE-2016-6554


JSON object : View

Products Affected

synology

  • ds213
  • ds107
  • ds213_firmware
  • ds107_firmware
  • ds116_firmware
  • ds116
CWE
CWE-255

Credentials Management Errors