First published: Wed Jun 23 2021(Updated: )
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.3-25426-3 | |
Synology Diskstation Manager Unified Controller | <3.1-23033 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27649 is critical with a severity value of 9.8.
CVE-2021-27649 affects Synology DiskStation Manager (DSM) before version 6.2.3-25426-3.
Yes, remote attackers can exploit CVE-2021-27649 to execute arbitrary code.
Yes, a fix is available for CVE-2021-27649. Users should update to Synology DiskStation Manager version 6.2.3-25426-3 or newer.
You can find more information about CVE-2021-27649 in the Synology security advisory: https://www.synology.com/security/advisory/Synology_SA_20_26