First published: Thu Oct 20 2022(Updated: )
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | <7.1.1-42962-2 | |
Synology Ds3622xs\+ | ||
Synology Fs3410 | ||
Synology Hd6500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3576 is high.
The models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 are affected by CVE-2022-3576.
CVE-2022-3576 allows remote attackers to obtain sensitive information via unspecified vectors by exploiting an out-of-bounds read vulnerability in the session processing functionality of Out-of-Band (OOB) Management.
No, Synology Ds3622xs+ is not vulnerable to CVE-2022-3576.
To fix CVE-2022-3576, update Synology DiskStation Manager (DSM) to version 7.1.1-42962-2 or later.