Tenable.ot Family for Tenable OT Security

IDNameSeverity
502462Synology DiskStation Manager Race Condition (CVE-2022-27626)
high
502461Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2014-2264)
high
502460Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2017-9554)
medium
502459Synology DiskStation Manager Path Traversal (CVE-2022-27610)
high
502458Synology DiskStation Manager Cross-site Scripting (CVE-2012-1556)
medium
502457Synology DiskStation Manager Improper Certificate Validation (CVE-2020-27648)
critical
502456Synology DiskStation Manager Use After Free (CVE-2021-27646)
critical
502455Synology DiskStation Manager Dnsmasq Out-of-bounds Write (CVE-2017-14491)
critical
502454Synology DiskStation Manager Observable Discrepancy (CVE-2017-5753)
medium
502453Synology DiskStation Manager Improper Neutralization of Input During Web Page Generation (CVE-2018-13293)
medium
502452Synology DiskStation Manager Incorrect Authorization (CVE-2021-26563)
medium
502451Synology DiskStation Manager Samba Use After Free (CVE-2019-19344)
medium
502450Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2021-29086)
high
502449Synology DiskStation Manager NTPD Denial of Service (CVE-2018-7184)
high
502448Synology DiskStation Manager Incorrect Default Permissions (CVE-2018-13286)
medium
502447Synology DiskStation Manager Improper Neutralization of Input During Web Page Generation (CVE-2017-16774)
medium
502446Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2022-22680)
high
502445Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2015-2809)
medium
502444Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2021-26566)
critical
502443Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2018-8919)
critical
502442Synology DiskStation Manager SYNO.API.Encryption API Protection Mechanism Bypass (CVE-2017-9553)
high
502441Synology DSM HTTP/2 Implementations Allocation of Resources Without Limits or Throttling (CVE-2019-9517)
high
502440Synology DiskStation Manager Path Traversal (CVE-2021-29088)
high
502439Synology DiskStation Manager Permissions, Privileges, and Access Controls (CVE-2013-6955)
critical
502438Synology DiskStation Manager SQL Injection (CVE-2021-43927)
critical
502437Synology DiskStation Manager Cleartext Transmission of Sensitive Information (CVE-2020-27656)
low
502436Synology DiskStation Uncontrolled Resource Consumption (CVE-2017-12076)
medium
502435Synology DiskStation Manager Netatalk Out-of-bounds Write (CVE-2018-1160)
critical
502434Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2018-13291)
medium
502433Synology DiskStation Manager Uncontrolled Search Path Element (CVE-2023-0142)
high
502432Synology DiskStation Manager OS Command Injection (CVE-2018-13284)
high
502431Synology DiskStation Manager Use of a Broken or Risky Cryptographic Algorithm (CVE-2020-27652)
high
502430Synology DiskStation Manager Improper Neutralization of Special Elements used in an OS Command (CVE-2022-27616)
high
502429Synology DiskStation Manager Server-Side Request Forgery (SSRF) (CVE-2022-27622)
medium
502428Synology Multiple NAS Servers Credentials Management Errors (CVE-2016-6554)
critical
502427Synology DiskStation Manager Exposure of Sensitive Information to an Unauthorized Actor (CVE-2018-13281)
medium
502426Synology DSM HTTP/2 Implementations Allocation of Resources Without Limits or Throttling (CVE-2019-9514)
high
502425Synology DiskStation Manager Cross-site Scripting (CVE-2010-2453)
medium
502424Synology DiskStation Manager Out-of-bounds Read (CVE-2021-27647)
critical
502423Synology DiskStation Manager OS Command Injection (CVE-2022-22684)
high
502422Synology DiskStation Manager Out-of-bounds Write (CVE-2021-31439)
high
502421Synology DiskStation Manager Cleartext Transmission of Sensitive Information (CVE-2021-26560)
high
502420Synology DiskStation Manager Injection (CVE-2017-16766)
medium
502419Synology DiskStation Manager Improper Neutralization of Special Elements used in an OS Command (CVE-2022-22688)
high
502418Synology DiskStation Manager Path Traversal (CVE-2021-29087)
high
502417Synology DiskStation Manager Cleartext Transmission of Sensitive Information (CVE-2021-26565)
medium
502416Synology DSM HTTP/2 Implementations Allocation of Resources Without Limits or Throttling (CVE-2019-9518)
high
502415Synology DiskStation Manager Cleartext Transmission of Sensitive Information (CVE-2021-26564)
high
502414Synology DiskStation Manager Samba Out-of-bounds Read (CVE-2019-14907)
medium
502413Synology DiskStation Manager Use of Insufficiently Random Values (CVE-2018-13280)
medium