CVE-2022-27611: Path Traversal
Published Jul 28, 2022
·Updated
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Affected Software
1 affected component
Synology Audio Station<6.5.4-3367
Event History
Jul 28, 2022
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-27611.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in webapi component in Synology Audio Station before 6.5.4-3367'.
3
What is the severity of CVE-2022-27611?
The severity of CVE-2022-27611 is high with a severity value of 8.1.
4
How does CVE-2022-27611 affect Synology Audio Station?
CVE-2022-27611 affects Synology Audio Station versions before 6.5.4-3367.
5
How can remote authenticated users exploit CVE-2022-27611?
Remote authenticated users can exploit CVE-2022-27611 to delete arbitrary files via unspecified vectors.