Show filters
300 Total Results
Displaying 71-80 of 300
Sort by:
Attacker Value
Unknown

CVE-2022-43748

Disclosure Date: October 26, 2022 (last updated December 22, 2024)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2022-27623

Disclosure Date: October 24, 2022 (last updated January 15, 2025)
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2022-27622

Disclosure Date: October 24, 2022 (last updated January 15, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
Attacker Value
Unknown

CVE-2022-27626

Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Attacker Value
Unknown

CVE-2022-3576

Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Attacker Value
Unknown

CVE-2022-27625

Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Attacker Value
Unknown

CVE-2022-27624

Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Attacker Value
Unknown

CVE-2022-27621

Disclosure Date: August 02, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology USB Copy before 2.2.0-1086 allows remote authenticated users to read or write arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2022-27620

Disclosure Date: August 02, 2022 (last updated October 08, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2022-27619

Disclosure Date: August 02, 2022 (last updated October 08, 2023)
Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.