Files
CVEs-PoC/2020/CVE-2020-27653.md
T
2024-05-25 21:48:12 +02:00

20 lines
896 B
Markdown

### [CVE-2020-27653](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27653)
![](https://img.shields.io/static/v1?label=Product&message=Synology%20Router%20Manager%20(SRM)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-327%3A%20Use%20of%20a%20Broken%20or%20Risky%20Cryptographic%20Algorithm&color=brighgreen)
### Description
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
### POC
#### Reference
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1061
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Live-Hack-CVE/CVE-2020-27653
- https://github.com/looran/synocli