First published: Tue Oct 25 2022(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | <7.1-42661 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27622 is a Server-Side Request Forgery (SSRF) vulnerability in the Package Center functionality in Synology DiskStation Manager (DSM) before version 7.1-42661.
CVE-2022-27622 allows remote authenticated users to access intranet resources through unspecified vectors.
The severity of CVE-2022-27622 is medium with a severity value of 4.3.
To fix CVE-2022-27622, users should update to Synology DiskStation Manager version 7.1-42661 or later.
More information about CVE-2022-27622 can be found in the Synology Security Advisory Synology_SA_22_18 at https://www.synology.com/security/advisory/Synology_SA_22_18.