First published: Mon Jan 24 2022(Updated: )
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.4-25556-3 | |
Synology DiskStation Manager | >=7.0<7.0.1-42218-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22680 is a vulnerability that allows remote attackers to obtain sensitive information in Synology DiskStation Manager (DSM) before version 7.0.1-42218-2.
The severity of CVE-2022-22680 is high with a severity value of 7.5.
The exposure of sensitive information can be exploited by remote attackers through unspecified vectors.
CVE-2022-22680 affects Synology DiskStation Manager (DSM) versions 6.2 to 6.2.4-25556-3 and 7.0 to 7.0.1-42218-2.
To fix CVE-2022-22680, it is recommended to update Synology DiskStation Manager (DSM) to version 7.0.1-42218-2 or later.