CVE-2017-15887
Description
CVE-2017-15887 allows remote attackers to brute-force user credentials against Synology CardDAV Server before 6.0.7-0085.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2017-15887 allows remote attackers to brute-force user credentials against Synology CardDAV Server before 6.0.7-0085.
Vulnerability
An improper restriction of excessive authentication attempts vulnerability exists in the /principals endpoint of Synology CardDAV Server before version 6.0.7-0085. This allows remote attackers to perform brute-force attacks without any prior authentication or special conditions [1].
Exploitation
An attacker can exploit this vulnerability by sending a high volume of authentication requests to the /principals endpoint from any network-connected location. No authentication or user interaction is required. The attacker systematically guesses or iterates over possible credentials until successful authentication is achieved [1].
Impact
Successful exploitation enables the attacker to obtain user credentials, potentially gaining access to system user accounts. This can lead to unauthorized access to sensitive data (confidentiality) and the ability to modify or delete data (integrity). The CVSS v3 base score is 9.1 (Critical) [1].
Mitigation
The vulnerability is fixed in CardDAV Server version 6.0.7-0085 and later. Users should update via DSM Package Center. No workarounds are available; updating is the only mitigation [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<6.0.7-0085+ 1 more
- (no CPE)range: <6.0.7-0085
- (no CPE)range: before 6.0.7-0085
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.synology.com/en-global/support/security/Synology_SA_17_64_CardDAV_ServernvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.