CVE-2017-5753
Synology
- Published
- 4 January 2018
- Last modified
- 17 June 2026
- CVSS
- 5.6 v3.1
- Severity
- medium
- EPSS
- 93.8% (100th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-203
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Description
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 93.8% probability of exploitation activity in the next 30 days, placing it in the top decile of all scored CVEs.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| VS360HD | Synology | unknown | — |
| VS960HD | Synology | unknown | < 2.2.3-1505, < 2.3.6-1720 |
References
Vendor advisory and patch
- https://cdrdv2.intel.com/v1/dl/getContent/685359
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002
- https://cdrdv2.intel.com/v1/dl/getContent/685359
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614 third-party
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html exploit
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt third-party
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt third-party
- http://www.kb.cert.org/vuls/id/584653 third-party
- http://www.securityfocus.com/bid/102371 third-party
- http://www.securitytracker.com/id/1040071 third-party
- http://xenbits.xen.org/xsa/advisory-254.html third-party
- https://access.redhat.com/errata/RHSA-2018:0292 third-party
- https://access.redhat.com/security/vulnerabilities/speculativeexecution third-party
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ third-party
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ third-party
- https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf third-party
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf third-party
- https://cert.vde.com/en-us/advisories/vde-2018-002 third-party
- https://cert.vde.com/en-us/advisories/vde-2018-003 third-party
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability third-party
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html third-party
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html third-party
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html third-party
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html third-party
- https://seclists.org/bugtraq/2019/Jun/36 third-party
- https://security.gentoo.org/glsa/201810-06 third-party
- https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html third-party
- https://security.netapp.com/advisory/ntap-20180104-0001/ third-party
- https://spectreattack.com/ third-party
- https://support.citrix.com/article/CTX231399 third-party
- https://support.f5.com/csp/article/K91229003 third-party
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us third-party
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us third-party
- https://support.lenovo.com/us/en/solutions/LEN-18282 third-party
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel third-party
- https://usn.ubuntu.com/3540-1/ third-party
- https://usn.ubuntu.com/3540-2/ third-party
- https://usn.ubuntu.com/3541-1/ third-party
- https://usn.ubuntu.com/3541-2/ third-party
- https://usn.ubuntu.com/3542-1/ third-party
- https://usn.ubuntu.com/3542-2/ third-party
- https://usn.ubuntu.com/3549-1/ third-party
- https://usn.ubuntu.com/3580-1/ third-party
- https://usn.ubuntu.com/3597-1/ third-party
- https://usn.ubuntu.com/3597-2/ third-party
- https://usn.ubuntu.com/usn/usn-3516-1/ third-party
- https://www.debian.org/security/2018/dsa-4187 third-party
- https://www.debian.org/security/2018/dsa-4188 third-party
- https://www.exploit-db.com/exploits/43427/ exploit
- https://www.kb.cert.org/vuls/id/180049 third-party
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 third-party
- https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ third-party
- https://www.synology.com/support/security/Synology_SA_18_01 third-party
- https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html third-party
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613 third-party
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614 third-party
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html exploit
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt third-party
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt third-party
- http://www.kb.cert.org/vuls/id/584653 third-party
- http://www.securityfocus.com/bid/102371 third-party
- http://www.securitytracker.com/id/1040071 third-party
- http://xenbits.xen.org/xsa/advisory-254.html third-party
- https://access.redhat.com/errata/RHSA-2018:0292 third-party
- https://access.redhat.com/security/vulnerabilities/speculativeexecution third-party
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ third-party
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ third-party
- https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf third-party
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf third-party
- https://cert.vde.com/en-us/advisories/vde-2018-002 third-party
- https://cert.vde.com/en-us/advisories/vde-2018-003 third-party
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability third-party
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html third-party
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html third-party
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html third-party
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html third-party
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html third-party
- https://seclists.org/bugtraq/2019/Jun/36 third-party
- https://security.gentoo.org/glsa/201810-06 third-party
- https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html third-party
- https://security.netapp.com/advisory/ntap-20180104-0001/ third-party
- https://spectreattack.com/ third-party
- https://support.citrix.com/article/CTX231399 third-party
- https://support.f5.com/csp/article/K91229003 third-party
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us third-party
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us third-party
- https://support.lenovo.com/us/en/solutions/LEN-18282 third-party
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel third-party
- https://usn.ubuntu.com/3540-1/ third-party
- https://usn.ubuntu.com/3540-2/ third-party
- https://usn.ubuntu.com/3541-1/ third-party
- https://usn.ubuntu.com/3541-2/ third-party
- https://usn.ubuntu.com/3542-1/ third-party
- https://usn.ubuntu.com/3542-2/ third-party
- https://usn.ubuntu.com/3549-1/ third-party
- https://usn.ubuntu.com/3580-1/ third-party
- https://usn.ubuntu.com/3597-1/ third-party
- https://usn.ubuntu.com/3597-2/ third-party
- https://usn.ubuntu.com/usn/usn-3516-1/ third-party
- https://www.debian.org/security/2018/dsa-4187 third-party
- https://www.debian.org/security/2018/dsa-4188 third-party
- https://www.exploit-db.com/exploits/43427/ exploit
- https://www.kb.cert.org/vuls/id/180049 third-party
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 third-party
- https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ third-party
- https://www.synology.com/support/security/Synology_SA_18_01 third-party
- https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html third-party
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.