PT-2026-95332 · Synology · Diskstation Manager
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Synology DiskStation Manager versions prior to 7.2.1-69057-12
Synology DiskStation Manager versions prior to 7.2.2-72806-9
Synology DiskStation Manager versions prior to 7.3.2-86009-4
Synology DiskStation Manager versions prior to 7.4-90075
Description
An external control of file name or path issue exists in the Upload API endpoint. This allows remote authenticated users to write arbitrary files to the system, which can lead to denial-of-service attacks.
Recommendations
Update to version 7.2.1-69057-12 or later.
Update to version 7.2.2-72806-9 or later.
Update to version 7.3.2-86009-4 or later.
Update to version 7.4-90075 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Diskstation Manager