CVE-2023-2729: Synology Diskstation Manager

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.

Affected products

  • Synology Diskstation Manager: from 6.2, before 7.2-64561 (fixed in 7.2-64561)
  • Synology Diskstation Manager Unified Controller: version 3.1 only
  • Synology Router Manager: from 1.2, before 1.3.1-9346 (fixed in 1.3.1-9346); version 1.3.1-9346 only

Published 2023-06-13. Last modified 2026-06-17.