First published: Mon Feb 07 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.4-25556-3 | |
Synology DiskStation Manager | >=7.0<7.0.1-42218-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-22679.
The severity level of CVE-2022-22679 is medium.
Synology DiskStation Manager versions from 6.2 to 6.2.4-25556-3 and versions from 7.0 to 7.0.1-42218-2 are affected by CVE-2022-22679.
CVE-2022-22679 allows remote authenticated users to write arbitrary files via unspecified vectors.
You can find more information about CVE-2022-22679 on the Synology security advisory page: https://www.synology.com/security/advisory/Synology_SA_22_01