CVE-2021-27646: (Pwn2Own) Synology DiskStation Manager iscsi_snapshot_comm_core Use-After-Free Remote Code Execution Vulnerability
Published Mar 12, 2021
·Updated
Use After Free vulnerability in iscsisnapshotcommcore in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
Affected Software
2 affected components
Synology Diskstation Manager<6.2.3-25426-3
Synology Diskstation Manager<6.2.3-25426-3
Event History
Mar 12, 2021
CVE Published
via MITRE·06:45 AM
Data Sourced
via MITRE·06:45 AM
DescriptionSeverityWeakness
Jan 14, 2025
Advisory Published
via ZDI·08:16 PM
Data Sourced
via ZDI·08:16 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-27646.
2
What is the severity of CVE-2021-27646?
The severity of CVE-2021-27646 is critical with a CVSS score of 9.8.
3
How can local attackers exploit CVE-2021-27646?
Local attackers can exploit CVE-2021-27646 to execute arbitrary code on affected installations of Synology DS418play.
4
Is authentication required to exploit CVE-2021-27646?
No, authentication is not required to exploit CVE-2021-27646.
5
What is the affected software for CVE-2021-27646?
The affected software for CVE-2021-27646 is Synology DiskStation Manager version up to 6.2.3-25426-3.