CVE-2018-13295: Synology Application Service

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter.

Affected products

  • Synology Application Service: before 1.5.4-0320 (fixed in 1.5.4-0320)

Published 2019-04-01. Last modified 2026-06-17.