CVE-2017-15887: Synology Carddav Server

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.

Affected products

  • Synology Carddav Server: before 6.0.7-0085 (fixed in 6.0.7-0085)

Published 2017-11-07. Last modified 2026-06-17.