CVE-2021-27647: (Pwn2Own) Synology DiskStation Manager StartEngCommPipeServer HandleSendMsg Out-Of-Bounds Read Information Disclosure Vulnerability
Published Mar 12, 2021
·Updated
Out-of-bounds Read vulnerability in iscsisnapshotcommcore in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
Affected Software
2 affected components
Synology Diskstation Manager<6.2.3-25426-3
Synology Diskstation Manager<6.2.3-25426-3
Event History
Mar 12, 2021
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionSeverityWeakness
Jan 14, 2025
Advisory Published
via ZDI·08:16 PM
Data Sourced
via ZDI·08:16 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-27647?
The severity of CVE-2021-27647 is critical with a CVSS score of 9.8.
2
How does CVE-2021-27647 affect Synology DiskStation Manager?
CVE-2021-27647 affects Synology DiskStation Manager versions up to and including 6.2.3-25426-3.
3
What is the vulnerability description of CVE-2021-27647?
CVE-2021-27647 is a vulnerability that allows network-adjacent attackers to disclose sensitive information on affected installations of Synology DS418play.
4
Is authentication required to exploit CVE-2021-27647?
No, authentication is not required to exploit CVE-2021-27647.
5
How can I find more information about CVE-2021-27647?
You can find more information about CVE-2021-27647 on the Synology and Zero Day Initiative websites.