Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Authentication Bypass via SSO in Synology DSM |
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2026-05-27T08:36:06.463Z
Reserved: 2025-11-19T00:37:57.748Z
Link: CVE-2025-13392
No data.
Status : Received
Published: 2026-05-27T09:16:26.607
Modified: 2026-05-27T09:16:26.607
Link: CVE-2025-13392
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:30:28Z