CVE-2022-27615: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27615?
CVE-2022-27615 is an improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in cgi component in Synology DNS Server before 2.2.2-5027.
How does CVE-2022-27615 affect Synology DNS Server?
CVE-2022-27615 allows remote authenticated users to delete arbitrary files in Synology DNS Server before 2.2.2-5027.
What is the severity of CVE-2022-27615?
The severity of CVE-2022-27615 is high, with a CVSS score of 8.1.
How can I fix the CVE-2022-27615 vulnerability?
To fix the CVE-2022-27615 vulnerability, update Synology DNS Server to version 2.2.2-5027 or later.
Where can I find more information about CVE-2022-27615?
You can find more information about CVE-2022-27615 at the following link: [Synology Security Advisory (Synology_SA_20_27)](https://www.synology.com/security/advisory/Synology_SA_20_27).