CVE-2022-22681: High severity synology photo station vulnerability
Published Jul 6, 2022
·Updated
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
Affected Software
1 affected component
Synology Photo Station<6.8.16-3506
Event History
Jul 6, 2022
CVE Published
via MITRE·07:35 AM
Data Sourced
via MITRE·07:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-22681.
2
What is the title of this vulnerability?
The title of this vulnerability is "Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506."
3
How does this vulnerability impact Synology Photo Station?
This vulnerability allows remote attackers to bypass security constraint in access control management in Synology Photo Station.
4
What is the severity of CVE-2022-22681?
The severity of CVE-2022-22681 is high with a CVSS score of 7.5.
5
How can I fix this vulnerability in Synology Photo Station?
To fix this vulnerability, update Synology Photo Station to version 6.8.16-3506 or later.