CVE-2021-27649: Use After Free
Published Jun 23, 2021
·Updated
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
3 affected components
Synology Diskstation Manager>=6.2<6.2.3-25426-3
Synology Diskstation Manager Unified Controller<3.1-23033
Synology Diskstation Manager>=6.2<6.2.3-25426-3
Event History
Jun 23, 2021
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27649?
The severity of CVE-2021-27649 is critical with a severity value of 9.8.
2
How does CVE-2021-27649 affect Synology DiskStation Manager (DSM)?
CVE-2021-27649 affects Synology DiskStation Manager (DSM) before version 6.2.3-25426-3.
3
Can remote attackers exploit CVE-2021-27649?
Yes, remote attackers can exploit CVE-2021-27649 to execute arbitrary code.
4
Is there a fix available for CVE-2021-27649?
Yes, a fix is available for CVE-2021-27649. Users should update to Synology DiskStation Manager version 6.2.3-25426-3 or newer.
5
Where can I find more information about CVE-2021-27649?
You can find more information about CVE-2021-27649 in the Synology security advisory: https://www.synology.com/security/advisory/Synology_SA_20_26