What is the synology CNA?
synology is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 275 CVE records since 2017.
How many CVEs has synology published?
synology has published 275 CVE records, including 75 in the last two years.
What is synology's CVE data quality grade?
RadicalNotion.AI grades synology's CVE data quality as A, with an overall completeness score of 91.9%. This reflects how consistently its CVE records include vendor (97.1%), product (97.1%), CVSS (81.1%), and CWE (92.4%) information.
What products does synology publish CVEs for?
synology most frequently publishes CVEs for diskstation manager, DiskStation Manager (DSM), router manager, Synology Router Manager (SRM), Photo Station.
Which vendors does synology cover?
synology publishes CVEs across 3 distinct vendors, most often Synology, microsoft, faad2 project, github/knik0, knik0.
Is synology actively publishing CVEs?
synology is currently active, based on 75 CVEs in the last two years.
What is the average severity of synology's CVEs?
The average CVSS base score across synology's scored CVEs is 6.8.
How many critical CVEs has synology published?
synology has published 30 critical-severity CVEs and 76 high-severity CVEs.
Are any of synology's CVEs in CISA's Known Exploited Vulnerabilities catalog?
No. None of synology's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
What are the most common weakness types in synology's CVEs?
synology's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
How does synology rank among CNAs?
By total CVE volume, synology ranks #74 of 370 CNAs, and it reports more complete CVE records than 38% of all CNAs.