CVE-2022-27610: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-27610?
Vulnerability CVE-2022-27610 is a 'Path Traversal' vulnerability in the webapi component in Synology DiskStation Manager (DSM) before version 6.2.3-25423.
What is the severity of vulnerability CVE-2022-27610?
The severity of vulnerability CVE-2022-27610 is high, with a severity score of 8.1.
Which software is affected by vulnerability CVE-2022-27610?
The vulnerability CVE-2022-27610 affects Synology DiskStation Manager (DSM) versions before 6.2.3-25423.
How does vulnerability CVE-2022-27610 work?
Vulnerability CVE-2022-27610 allows remote authenticated users to delete arbitrary files through a 'Path Traversal' attack.
Is there a fix or patch available for vulnerability CVE-2022-27610?
Yes, Synology has released a fix for vulnerability CVE-2022-27610. It is recommended to upgrade Synology DiskStation Manager (DSM) to version 6.2.3-25423 or newer.