CVE-2017-9552: Synology Photo Station
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
Affected products
- Synology Photo Station: version 6.0-2528 only; version 6.0-2636 only; version 6.0-2638 only; version 6.0-2639 only; version 6.0-2640 only; version 6.3-2944 only; …
Published 2017-06-13. Last modified 2026-06-17.