CVE-2021-34812 is a high-severity vulnerability affecting Synology Calendar versions prior to 2.4.0-0761, stemming from the use of hard-coded credentials within a PHP component. This flaw allows remote attackers to gain unauthorized access to sensitive information without requiring authentication or user interaction. While the CVSS score is 7.5, indicating a significant risk, there is currently no evidence of active exploitation, publicly available exploit code, or notable community discussion surrounding this vulnerability. Organizations using affected Synology Calendar versions should prioritize updating to the patched release to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.0-0761CPE matchmatch criteria | cpe:2.3:a:synology:calendar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.