CVE-2023-2729: Synology Diskstation Manager
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
Affected products
- Synology Diskstation Manager: from 6.2, before 7.2-64561 (fixed in 7.2-64561)
- Synology Diskstation Manager Unified Controller: version 3.1 only
- Synology Router Manager: from 1.2, before 1.3.1-9346 (fixed in 1.3.1-9346); version 1.3.1-9346 only
Published 2023-06-13. Last modified 2026-06-17.