CVE-2022-27621: Path Traversal
Published Aug 3, 2022
·Updated
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology USB Copy before 2.2.0-1086 allows remote authenticated users to read or write arbitrary files via unspecified vectors.
Affected Software
8 affected components
Synology USB Copy<2.2.0-1086
Synology Diskstation Manager=6.2
Synology Diskstation Manager=7.0
Synology Diskstation Manager=7.1
All of the following
Synology USB Copy<2.2.0-1086
Any of the following
Synology Diskstation Manager=6.2
Synology Diskstation Manager=7.0
Synology Diskstation Manager=7.1
Event History
Aug 3, 2022
CVE Published
via MITRE·05:55 AM
Data Sourced
via MITRE·05:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-27621.
2
What is the severity of CVE-2022-27621?
The severity of CVE-2022-27621 is medium.
3
Which component is affected by CVE-2022-27621?
The webapi component in Synology USB Copy before 2.2.0-1086 is affected by CVE-2022-27621.
4
How can remote authenticated users exploit CVE-2022-27621?
Remote authenticated users can exploit CVE-2022-27621 to read or write arbitrary files via unspecified vectors.
5
Is Synology DiskStation Manager vulnerable to CVE-2022-27621?
No, Synology DiskStation Manager versions 6.2, 7.0, and 7.1 are not vulnerable to CVE-2022-27621.