Path Traversal Vulnerability in Synology DiskStation Manager
CVE-2021-29087

7.5HIGH

Key Information:

Vendor

Synology

Vendor
CVE Published:
23 June 2021

What is CVE-2021-29087?

An improper limitation of a pathname to a restricted directory in the webapi component of Synology DiskStation Manager allows remote attackers to exploit this vulnerability. By leveraging unresolved vectors, they may gain the ability to write arbitrary files on the system, potentially leading to further exploits or data compromise. Users are encouraged to update to version 6.2.3-25426-3 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DiskStation Manager (DSM) < 6.2.3-25426-3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.