CVE-2021-26562: Critical severity synology photos diskstation manager vulnerability
Published Feb 26, 2021
·Updated
Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via synofindersite HTTP header.
Affected Software
14 affected components
Synology Diskstation Manager<6.2.3-25426-3
All of the following
Synology Vs960hd Firmware
Synology Vs960hd
All of the following
Synology Skynas Firmware
Synology Skynas
All of the following
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Synology Diskstation Manager<6.2.3-25426-3
Synology Vs960hd Firmware
Synology Vs960hd
Synology Skynas Firmware
Synology Skynas
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Event History
Feb 26, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-26562.
2
What is the severity of CVE-2021-26562?
The severity of CVE-2021-26562 is critical with a severity value of 8.1.
3
Which software is affected by CVE-2021-26562?
Synology DiskStation Manager (DSM) before 6.2.3-25426-3 is affected by CVE-2021-26562.
4
How can a man-in-the-middle attacker exploit CVE-2021-26562?
A man-in-the-middle attacker can exploit CVE-2021-26562 by using the syno_finder_site HTTP header to execute arbitrary code.
5
How can I fix CVE-2021-26562?
To fix CVE-2021-26562, it is recommended to update Synology DiskStation Manager (DSM) to version 6.2.3-25426-3 or later.