First published: Wed Nov 15 2017(Updated: )
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photos Diskstation Manager | >=5.2<5.2-5967-6 | |
Synology Photos Diskstation Manager | >=6.0<6.0.3-8754-3 | |
Synology Photos Diskstation Manager | >=5.2<5.2-5967-6 | |
Synology Photos Diskstation Manager | >=6.0<6.0.3-8754-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15894 is classified as a medium severity vulnerability in Synology DiskStation Manager.
To fix CVE-2017-15894, update Synology DiskStation Manager to the latest version that patches this vulnerability.
CVE-2017-15894 allows remote authenticated users to write arbitrary files by exploiting the dest_folder_path parameter.
CVE-2017-15894 affects Synology DiskStation Manager versions before 6.0.3-8754-3 and 5.2-5967-6.
Yes, CVE-2017-15894 can only be exploited by remote authenticated users.