CVE-2017-15887: Synology Carddav Server
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
Affected products
- Synology Carddav Server: before 6.0.7-0085 (fixed in 6.0.7-0085)
Published 2017-11-07. Last modified 2026-06-17.