Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.synology.com/security/advisory/Synology_SA_20_14 | Vendor Advisory | 
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1061 | Exploit Third Party Advisory | 
| https://www.synology.com/security/advisory/Synology_SA_20_14 | Vendor Advisory | 
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1061 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    14 Jan 2025, 19:29
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:synology:diskstation_manager:6.2.3_25426:*:*:*:*:*:*:* | 
Information
                Published : 2020-10-29 09:15
Updated : 2025-01-14 19:29
NVD link : CVE-2020-27653
Mitre link : CVE-2020-27653
CVE.ORG link : CVE-2020-27653
JSON object : View
Products Affected
                synology
- router_manager
- diskstation_manager
CWE
                
                    
                        
                        CWE-327
                        
            Use of a Broken or Risky Cryptographic Algorithm
