Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

Sat, 30 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Wed, 27 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass via SSO in Synology DSM

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published: 2026-05-27T08:36:06.463Z

Updated: 2026-05-27T13:44:34.268Z

Reserved: 2025-11-19T00:37:57.748Z

Link: CVE-2025-13392

cve-icon Vulnrichment

Updated: 2026-05-27T13:44:30.948Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T09:16:26.607

Modified: 2026-06-02T20:42:40.143

Link: CVE-2025-13392

cve-icon Redhat

No data.