CVE-2017-9552

high
Published 2017-06-13 ยท Modified 2026-05-13
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

Predictions

Exploit likelihood
75%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
synologyphoto_station6.0-2528
synologyphoto_station6.0-2636
synologyphoto_station6.0-2638
synologyphoto_station6.0-2639
synologyphoto_station6.0-2640
synologyphoto_station6.3-2944
synologyphoto_station6.3-2958
synologyphoto_station6.3-2960
synologyphoto_station6.3-2962
synologyphoto_station6.3-2963
synologyphoto_station6.3-2964
synologyphoto_station6.3-2965
synologyphoto_station6.4-3166
synologyphoto_station6.5.0-3218
synologyphoto_station6.5.1-3223
synologyphoto_station6.5.2-3225
synologyphoto_station6.5.3-3226
synologyphoto_station6.6.0-3339
synologyphoto_station6.6.1-3345
synologyphoto_station6.6.1-3346
synologyphoto_station6.6.2-3346
synologyphoto_station6.6.3-3347
synologyphoto_station6.7.0-3414
synologyphoto_station6.7.1-3419

References

CWEs

CWE-522 CWE-287

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.