Description
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Problem types
Improper Check for Unusual or Exceptional Conditions
Product status
7.3 (semver) before 7.3.1-86003-1
7.2.2 (semver) before 7.2.2-72806-5
7.2.1 (semver) before 7.2.1.*
Any version before 7.2.1
Credits
Le Trong Phuc (chanze@VRC) and Cao Ngoc Quy (Chino Kafuu)
References
www.synology.com/...obal/security/advisory/Synology_SA_25_14 (Synology-SA-25:14 DSM (PWN2OWN 2025))