Integer Overflow Vulnerability in Synology Router Management Software
CVE-2023-0077

6.5MEDIUM

Key Information:

Vendor
Synology
Vendor
CVE Published:
5 January 2023

Summary

An integer overflow vulnerability exists in the CGI component of Synology Router Manager, affecting versions prior to 1.2.5-8227-6 and 1.3.1-9346-3. This flaw allows remote attackers to exploit unspecified vectors that result in buffer overflow, potentially compromising the security of the affected system. It is crucial for users to update their devices to mitigate security risks and protect their network integrity.

Affected Version(s)

Synology Router Manager (SRM) 1.2

Synology Router Manager (SRM) 1.2 < 1.2.5-8227-6

Synology Router Manager (SRM) 1.3 < 1.3.1-9346-3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.