Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
affected
7.2.2 (semver) before 7.2.2-72806
affected
7.2.1 (semver) before 7.2.1-69057-2
affected
Any version before 7.2.1
unknown
Default status
affected
3.1 (semver) before 3.1.4-23079
affected
Any version before 3.1
unknown
Description
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.
Problem types
Improper Control of Dynamically-Managed Code Resources
Product status
7.2.2 (semver) before 7.2.2-72806
7.2.1 (semver) before 7.2.1-69057-2
Any version before 7.2.1
3.1 (semver) before 3.1.4-23079
Any version before 3.1
Credits
Vo Van Thong of GE Security (VNG) (https://www.linkedin.com/in/thongvv3/)
References
www.synology.com/...obal/security/advisory/Synology_SA_24_27 (Synology-SA-24:27 DSM)