First published: Tue Jun 01 2021(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Video Station | <2.4.10-1632 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33181 has a medium severity rating, as it concerns SSRF that can be exploited by authenticated users.
To fix CVE-2021-33181, update Synology Video Station to version 2.4.10-1632 or later.
CVE-2021-33181 affects users of Synology Video Station versions prior to 2.4.10-1632.
CVE-2021-33181 allows remote authenticated users to conduct Server-Side Request Forgery attacks to intranet resources.
CVE-2021-33181 was disclosed on April 21, 2021, detailing the vulnerability in Synology's webapi component.