CVE-2022-22687: Buffer Overflow
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22687?
CVE-2022-22687 is a buffer overflow vulnerability in the Authentication functionality of Synology DiskStation Manager (DSM) before version 6.2.3-25426-3.
What is the severity of CVE-2022-22687?
CVE-2022-22687 has a severity level of 9.8 (Critical).
How does CVE-2022-22687 work?
CVE-2022-22687 occurs when there is a buffer copy without checking the size of input, allowing remote attackers to execute arbitrary code.
Which software versions are affected by CVE-2022-22687?
The Authentication functionality in Synology DiskStation Manager (DSM) versions before 6.2.3-25426-3 are affected by CVE-2022-22687.
How can I fix CVE-2022-22687?
To fix CVE-2022-22687, users should update their Synology DiskStation Manager (DSM) to version 6.2.3-25426-3 or later.