CVE-2021-27649Use After Free in Synology Diskstation Manager

CWE-416Use After Free3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
1.5%
top 19.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateMay 24

Description

Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5synology/diskstation_managerunspecified6.2.3-25426-3
NVDsynology/diskstation_manager6.26.2.3-25426-3

🔴Vulnerability Details

2
GHSA
GHSA-59pm-73xx-3pvc: Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 62022-05-24
CVEList
CVE-2021-27649: Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 62021-06-23
CVE-2021-27649 — Use After Free in Synology | cvebase