Synology NAS DSM Account Takeover: When Random is not Secure
ID: 81f26cd4-5e12-546b-bf53-a69eab5933ef
STIX ID: report--81f26cd4-5e12-546b-bf53-a69eab5933ef
Feed Name: Claroty Team82
Threat Score
Team82 discovered that Synology DSM's installation wizard used the insecure JavaScript Math.random() to generate the built-in admin password, enabling an attacker who can leak several Math.random()-derived GUIDs to reconstruct the XorShift128 PRNG seed and recover the admin password; the team produced a PoC, disclosed the issue as CVE-2023-2729, and Synology released a patch (DSM 7.2-64561+).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
