Uncontrolled Search Path Vulnerability in Synology DiskStation Manager
CVE-2023-0142
8.1HIGH
Key Information:
- Vendor
Synology
- Vendor
- CVE Published:
- 13 June 2023
What is CVE-2023-0142?
The vulnerability in the Backup Management functionality of Synology DiskStation Manager enables remote authenticated users with administrator privileges to manipulate file access. This can result in unauthorized reading or writing of arbitrary files due to unspecified vectors. Users should take immediate action to update affected versions to mitigate potential risks associated with this flaw.
Affected Version(s)
DiskStation Manager (DSM) 7.2
DiskStation Manager (DSM) 7.1 < 7.1-42661
DiskStation Manager (DSM) 7.0 < 7.0.1-42218-7