CVE-2017-11149: SSRF
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11149?
CVE-2017-11149 has a high severity due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2017-11149?
To fix CVE-2017-11149, upgrade Synology Download Station to the latest version available, specifically version 3.8.5-3475 or later.
Who is affected by CVE-2017-11149?
CVE-2017-11149 affects users of Synology Download Station versions prior to 3.8.5-3475 and 3.x versions before 3.5-2984.
What type of vulnerability is CVE-2017-11149?
CVE-2017-11149 is classified as a server-side request forgery (SSRF) vulnerability.
Can CVE-2017-11149 allow attackers to exploit my system remotely?
Yes, CVE-2017-11149 can be exploited by remote authenticated users to download arbitrary local files.