CVE-2021-29088Path Traversal in Synology Diskstation Manager

CWE-22Path Traversal3 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 88.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMay 24

Description

Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDsynology/diskstation_manager< 6.2.4-25553
CVEListV5synology/synology_diskstation_managerunspecified6.2.4-25553

🔴Vulnerability Details

2
GHSA
GHSA-88jq-fmhx-7gr3: Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 62022-05-24
CVEList
CVE-2021-29088: Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 62021-06-01
CVE-2021-29088 — Path Traversal in Synology | cvebase