Server-Side Request Forgery Vulnerability in Synology Video Station
CVE-2021-33181
6.6MEDIUM
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in the webapi component of Synology Video Station versions prior to 2.4.10-1632. This flaw permits authenticated remote users to send malicious requests to internal intranet resources, potentially exposing sensitive data or services. Effective mitigation strategies should be implemented to protect against unauthorized access and exploitation of this vulnerability.
Affected Version(s)
Synology Video Station < 2.4.10-1632
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved