CVE-2022-43931: Critical severity synology vpn plus server vulnerability
Published Jan 3, 2023
·Updated
Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.
Affected Software
8 affected components
All of the following
Synology VPN Plus Server<1.4.3-0534
Synology Router Manager=1.2
All of the following
Synology VPN Plus Server<1.4.4-0635
Synology Router Manager=1.3
Synology VPN Plus Server<1.4.3-0534
Synology Router Manager=1.2
Synology VPN Plus Server<1.4.4-0635
Synology Router Manager=1.3
Event History
Jan 3, 2023
CVE Published
via MITRE·03:11 AM
Data Sourced
via MITRE·03:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2022-43931.
2
What is the severity level of CVE-2022-43931?
The severity level of CVE-2022-43931 is critical.
3
Which software versions are affected by CVE-2022-43931?
Synology VPN Plus Server versions before 1.4.3-0534 and 1.4.4-0635 are affected by CVE-2022-43931.
4
How can remote attackers exploit CVE-2022-43931?
Remote attackers can exploit CVE-2022-43931 to execute arbitrary commands via unspecified vectors.
5
Is Synology Router Manager affected by CVE-2022-43931?
No, Synology Router Manager is not affected by CVE-2022-43931.