CVE-2022-43748: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology Presto File Serverto a version that resolves this vulnerability.Fixed in 2.1.2-1601
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-43748.
What is the severity of CVE-2022-43748?
The severity of CVE-2022-43748 is high with a severity value of 7.5.
What software is affected by CVE-2022-43748?
The Synology Presto File Server version up to 2.1.2-1601 is affected by CVE-2022-43748.
How does CVE-2022-43748 work?
CVE-2022-43748 is a path traversal vulnerability that allows remote attackers to write arbitrary files by bypassing directory restrictions.
Is there a fix available for CVE-2022-43748?
Yes, Synology has released a fix for CVE-2022-43748. Please refer to their security advisory [here](https://www.synology.com/security/advisory/Synology_SA_22_19) for more information.