First published: Thu Jul 28 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DNS Server | <2.2.2-5027 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27615 is an improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in cgi component in Synology DNS Server before 2.2.2-5027.
CVE-2022-27615 allows remote authenticated users to delete arbitrary files in Synology DNS Server before 2.2.2-5027.
The severity of CVE-2022-27615 is high, with a CVSS score of 8.1.
To fix the CVE-2022-27615 vulnerability, update Synology DNS Server to version 2.2.2-5027 or later.
You can find more information about CVE-2022-27615 at the following link: [Synology Security Advisory (Synology_SA_20_27)](https://www.synology.com/security/advisory/Synology_SA_20_27).