CVE-2021-26569: (Pwn2Own) Synology DiskStation Manager iscsi_snapshot_comm_core Race Condition Use-After-Free Remote Code Execution Vulnerability
Published Mar 12, 2021
·Updated
Race Condition within a Thread vulnerability in iscsisnapshotcommcore in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
Affected Software
2 affected components
Synology Diskstation Manager<6.2.3-25426-3
Synology Diskstation Manager<6.2.3-25426-3
Event History
Mar 12, 2021
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionSeverityWeakness
Jan 14, 2025
Advisory Published
via ZDI·08:16 PM
Data Sourced
via ZDI·08:16 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2021-26569?
CVE-2021-26569 is a vulnerability that allows local attackers to execute arbitrary code on affected installations of Synology DS418play.
2
What is the severity of CVE-2021-26569?
CVE-2021-26569 has a severity of critical with a CVSS score of 8.1.
3
Which software is affected by CVE-2021-26569?
CVE-2021-26569 affects Synology DiskStation Manager versions up to 6.2.3-25426-3.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by local attackers without requiring authentication.
5
Is there a fix for CVE-2021-26569?
Yes, Synology has released a security advisory providing information on how to mitigate this vulnerability.