CVE-2017-11151: Critical severity Synology Photo Station vulnerability
Published Aug 8, 2017
·Updated
A vulnerability in synothemeupload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logoupload action.
Affected Software
2 affected components
Synology Photo Station<=6.7.2-3429
Synology Photo Station=6.3-2967
Event History
Aug 8, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11151?
CVE-2017-11151 is considered a high-severity vulnerability due to its potential for arbitrary file uploads.
2
How do I fix CVE-2017-11151?
To fix CVE-2017-11151, update your Synology Photo Station to version 6.7.3-3432 or later.
3
What can attackers do with CVE-2017-11151?
Attackers can exploit CVE-2017-11151 to upload arbitrary files without authentication, leading to possible remote code execution.
4
Which versions of Synology Photo Station are affected by CVE-2017-11151?
CVE-2017-11151 affects Synology Photo Station versions before 6.7.3-3432 and specifically version 6.3-2967.
5
Is authentication required to exploit CVE-2017-11151?
No, CVE-2017-11151 allows exploitation without any form of authentication.