CVE-2018-13297: Infoleak
Published Apr 1, 2019
·Updated
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsmpath parameter.
Affected Software
2 affected components
Synology Drive Server<1.1.2-10562
Synology Drive<1.1.2-10562
Event History
Apr 1, 2019
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-13297?
CVE-2018-13297 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-13297?
To fix CVE-2018-13297, update Synology Drive to version 1.1.2-10562 or later.
3
What impacts does CVE-2018-13297 have on my system?
CVE-2018-13297 can allow remote attackers to access sensitive system information if exploited.
4
Which versions of Synology Drive are affected by CVE-2018-13297?
CVE-2018-13297 affects Synology Drive versions prior to 1.1.2-10562.
5
Can CVE-2018-13297 be exploited remotely?
Yes, CVE-2018-13297 can be exploited remotely through manipulation of the dsm_path parameter.