Path Traversal Vulnerability in Synology Presto File Server
CVE-2022-43748

5.8MEDIUM

Key Information:

Vendor
Synology
Vendor
CVE Published:
26 October 2022

Summary

A path traversal vulnerability exists in the file operation management of Synology Presto File Server prior to version 2.1.2-1601. This flaw allows remote attackers to exploit the system by writing arbitrary files to restricted directories through unspecified methods. Organizations utilizing this file server should take immediate action to mitigate potential risks associated with unauthorized file access and ensure their systems are updated to the latest version.

Affected Version(s)

Presto File Server < 2.1.2-1601

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.