First published: Fri Mar 25 2022(Updated: )
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.3-25426-3 | |
Synology Diskstation Manager Unified Controller | <3.1-23033 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22687 is a buffer overflow vulnerability in the Authentication functionality of Synology DiskStation Manager (DSM) before version 6.2.3-25426-3.
CVE-2022-22687 has a severity level of 9.8 (Critical).
CVE-2022-22687 occurs when there is a buffer copy without checking the size of input, allowing remote attackers to execute arbitrary code.
The Authentication functionality in Synology DiskStation Manager (DSM) versions before 6.2.3-25426-3 are affected by CVE-2022-22687.
To fix CVE-2022-22687, users should update their Synology DiskStation Manager (DSM) to version 6.2.3-25426-3 or later.