CVE-2021-33181: SSRF
Published Jun 1, 2021
·Updated
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
Affected Software
1 affected component
Synology Video Station<2.4.10-1632
Event History
Jun 1, 2021
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-33181?
CVE-2021-33181 has a medium severity rating, as it concerns SSRF that can be exploited by authenticated users.
2
How do I fix CVE-2021-33181?
To fix CVE-2021-33181, update Synology Video Station to version 2.4.10-1632 or later.
3
Who is affected by CVE-2021-33181?
CVE-2021-33181 affects users of Synology Video Station versions prior to 2.4.10-1632.
4
What types of attacks can be executed due to CVE-2021-33181?
CVE-2021-33181 allows remote authenticated users to conduct Server-Side Request Forgery attacks to intranet resources.
5
When was CVE-2021-33181 disclosed?
CVE-2021-33181 was disclosed on April 21, 2021, detailing the vulnerability in Synology's webapi component.