CVE-2022-27616: OS Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27616?
CVE-2022-27616 refers to an OS Command Injection vulnerability in the webapi component of Synology DiskStation Manager (DSM) versions 6.2 and 7.0.1-42218-3.
What is the severity of CVE-2022-27616?
The severity of CVE-2022-27616 is high with a CVSS score of 7.2.
What is the affected software of CVE-2022-27616?
The affected software is Synology DiskStation Manager (DSM) versions 6.2 and 7.0.1-42218-3.
How does CVE-2022-27616 exploit the vulnerability?
CVE-2022-27616 allows remote authenticated users to execute arbitrary commands via unspecified vectors that exploit the OS Command Injection vulnerability in the webapi component of Synology DiskStation Manager (DSM).
Is there a fix for CVE-2022-27616?
Yes, a fix is available for CVE-2022-27616. Users should update their Synology DiskStation Manager (DSM) to version 7.0.1-42218-3 or apply the necessary security patch.