CVE-2022-3576: High severity synology photos diskstation manager vulnerability
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3576?
The severity of CVE-2022-3576 is high.
Which models of Synology DiskStation Manager (DSM) are affected by CVE-2022-3576?
The models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 are affected by CVE-2022-3576.
How does CVE-2022-3576 work?
CVE-2022-3576 allows remote attackers to obtain sensitive information via unspecified vectors by exploiting an out-of-bounds read vulnerability in the session processing functionality of Out-of-Band (OOB) Management.
Is Synology Ds3622xs+ vulnerable to CVE-2022-3576?
No, Synology Ds3622xs+ is not vulnerable to CVE-2022-3576.
How can I fix CVE-2022-3576?
To fix CVE-2022-3576, update Synology DiskStation Manager (DSM) to version 7.1.1-42962-2 or later.