First published: Wed Oct 26 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Presto File Server | <2.1.2-1601 | |
<2.1.2-1601 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43748.
The severity of CVE-2022-43748 is high with a severity value of 7.5.
The Synology Presto File Server version up to 2.1.2-1601 is affected by CVE-2022-43748.
CVE-2022-43748 is a path traversal vulnerability that allows remote attackers to write arbitrary files by bypassing directory restrictions.
Yes, Synology has released a fix for CVE-2022-43748. Please refer to their security advisory [here](https://www.synology.com/security/advisory/Synology_SA_22_19) for more information.