CVE-2022-27624: Buffer Overflow
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-27624.
What is the severity rating of CVE-2022-27624?
The severity rating of CVE-2022-27624 is critical with a value of 9.8.
Which software is affected by CVE-2022-27624?
The Synology DiskStation Manager with version up to 7.1.1-42962-2 is affected by CVE-2022-27624.
How can this vulnerability be exploited?
Remote attackers can execute arbitrary commands by exploiting this vulnerability through unspecified vectors.
Is there a fix available for CVE-2022-27624?
It is recommended to refer to the Synology Security Advisory Synology_SA_22_17 for information on available fixes and mitigations.