Back to Database
Status published
High
CVE-2014-2264
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update...
Vulnerability Description
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2264
Credits & Attribution
No credits recorded in the NVD database.
References
More from synology
View All →CVE-2017-9554
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager...
Medium
5.3
CVE-2017-9553
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM)...
High
7.5
CVE-2017-16768
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology...
Medium
4.8
CVE-2017-12077
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager...
Medium
4.9
CVE-2017-12076
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM)...
Medium
4.9
Affected Vendor
synology
View all reports →Affected Software
diskstation manager
Vulnerable Versions:
4.3-3810
Timeline
Official Publish:
March 2nd, 2014
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.