High severity8.3NVD Advisory· Published Oct 29, 2020· Updated Jun 17, 2026
CVE-2020-27648
CVE-2020-27648
Description
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=6.2,<6.2.3-25426-2
- (no CPE)range: <6.2.3-25426-2
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- www.talosintelligence.com/vulnerability_reports/TALOS-2020-1058nvdExploitThird Party Advisory
- www.synology.com/security/advisory/Synology_SA_20_18nvdVendor Advisory
News mentions
0No linked articles in our index yet.