Vulnerability record · CVE-2017-9554 · published 24 July 2017
CVE-2017-9554: Synology DSM forget_passwd.cgi username enumeration
Synology · Diskstation Manager
Synology DiskStation Manager (DSM) before 6.1.3-15152 contains an information exposure flaw in forget_passwd.cgi that lets remote attackers enumerate valid usernames. Because the endpoint is reachable without authentication, it gives attackers a reliable way to build a list of real accounts before password attacks.
Description
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityThe flaw only exposes username validity and requires no authentication, but it is a useful reconnaissance step that feeds credential attacks and has high EPSS with a public exploit.
What it is
Synology DiskStation Manager (DSM) before 6.1.3-15152 contains an information exposure flaw in forget_passwd.cgi that lets remote attackers enumerate valid usernames. Because the endpoint is reachable without authentication, it gives attackers a reliable way to build a list of real accounts before password attacks.
Impact
An attacker learns which usernames exist on the DSM instance, improving the efficiency of brute-force, credential-stuffing or phishing attempts. No passwords or session data are exposed by this flaw itself.
Attack surface
Reachable over the network through the forget_passwd.cgi endpoint; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the DSM web interface can attempt enumeration.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76716 (99.52nd percentile) and a public Exploit-DB entry exists, indicating observed or likely active exploitation interest.
What to do
- Upgrade DSM to 6.1.3-15152 or later per Synology advisory SA_17_29_DSM.
- Restrict network access to the DSM web interface to trusted management networks or VPN.
- Enable account lockout and rate limiting on authentication and password-reset endpoints.
- Disable or block the forget_passwd.cgi endpoint if password reset is not needed.
- Monitor for repeated requests to forget_passwd.cgi from single sources.
Detection
- Alert on high-volume or sequential requests to forget_passwd.cgi from one source IP.
- Correlate username enumeration attempts with subsequent failed login bursts against DSM.
- Review DSM web access logs for password-reset requests from unexpected external addresses.
- Track requests to forget_passwd.cgi that return differing responses for valid versus invalid usernames.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/43455/ | |
| https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSM | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/43455/ | |
| https://www.synology.com/en-global/support/security/Synology_SA_17_29_DSM | MitigationVendor Advisory |
Track CVE-2017-9554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.