Vulnerability record · CVE-2017-11155 · published 8 August 2017
CVE-2017-11155: Synology Photo Station index.php information exposure
Synology · Photo Station
Synology Photo Station before 6.7.3-3432 and 6.3-2967 exposes sensitive system information through index.php. The flaw is remotely reachable without authentication and leaks data that can aid further attacks against the appliance.
Description
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote information disclosure with a high CVSS score, public exploit code, and very high EPSS probability, though not known to be actively exploited in KEV.
What it is
Synology Photo Station before 6.7.3-3432 and 6.3-2967 exposes sensitive system information through index.php. The flaw is remotely reachable without authentication and leaks data that can aid further attacks against the appliance.
Impact
An unauthenticated attacker can read sensitive system information from the Photo Station web interface. That information can be used to fingerprint the device and plan follow-on exploitation.
Attack surface
Reached over the network via HTTP requests to index.php on the Photo Station web service. The CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.47432 (98.8th percentile) and an Exploit-DB entry exists, indicating public exploit code is available.
What to do
- Upgrade Photo Station to 6.7.3-3432 or later (or 6.3-2967 or later on the 6.3 branch) per Synology SA_17_34_PhotoStation.
- If patching is delayed, restrict network access to Photo Station to trusted networks or place it behind a VPN.
- Disable or remove Photo Station if it is not required on the NAS.
- Review NAS logs for unusual requests to index.php and rotate any credentials or tokens that may have been exposed.
Detection
- Monitor web logs for anomalous or repeated requests to Photo Station index.php from untrusted sources.
- Alert on access to Photo Station from external IP addresses or unexpected geographies.
- Correlate Photo Station access with subsequent authentication attempts or exploitation activity on the NAS.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/42434/ | Third Party AdvisoryVDB Entry |
| https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation | Vendor Advisory |
| https://www.exploit-db.com/exploits/42434/ | Third Party AdvisoryVDB Entry |
| https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation | Vendor Advisory |
Track CVE-2017-11155 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.