CVE-2022-43931

10CRITICAL

Key Information

Vendor
Synology
Status
Vpn Plus Server
Vendor
CVE Published:
3 January 2023

Summary

Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.

Affected Version(s)

VPN Plus Server <= *

VPN Plus Server < 1.4.4-0635

VPN Plus Server < 1.4.3-0534

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.