PT-2018-11724 · Synology · Synology Diskstation Manager

CVE-2018-13281

·

Publicado

2018-10-31

·

Atualizado

2025-01-14

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 6.2-23739-2
Description The issue allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file path parameter. This is related to an information exposure vulnerability in SYNO.Core.ACL.
Recommendations For versions prior to 6.2-23739-2, update to version 6.2-23739-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the file path parameter to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-13281

Produtos afetados

Synology Diskstation Manager