CVE-2017-15894: Path Traversal
Published Dec 8, 2017
·Updated
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the destfolderpath parameter.
Affected Software
4 affected components
Synology Diskstation Manager>=5.2<5.2-5967-6
Synology Diskstation Manager>=6.0<6.0.3-8754-3
Synology Diskstation Manager>=5.2<5.2-5967-6
Synology Diskstation Manager>=6.0<6.0.3-8754-3
Event History
Dec 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-15894?
CVE-2017-15894 is classified as a medium severity vulnerability in Synology DiskStation Manager.
2
How do I fix CVE-2017-15894?
To fix CVE-2017-15894, update Synology DiskStation Manager to the latest version that patches this vulnerability.
3
What does CVE-2017-15894 allow an attacker to do?
CVE-2017-15894 allows remote authenticated users to write arbitrary files by exploiting the dest_folder_path parameter.
4
Which versions of Synology DiskStation Manager are affected by CVE-2017-15894?
CVE-2017-15894 affects Synology DiskStation Manager versions before 6.0.3-8754-3 and 5.2-5967-6.
5
Is user authentication required to exploit CVE-2017-15894?
Yes, CVE-2017-15894 can only be exploited by remote authenticated users.