CVE-2022-43932: High severity synology router manager vulnerability
Published Jan 5, 2023
·Updated
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
2 affected components
Synology Router Manager>=1.2<1.2.5-8227-6
Synology Router Manager>=1.3<1.3.1-9346-3
Event History
Jan 5, 2023
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID is CVE-2022-43932.
2
What is the severity of CVE-2022-43932?
The severity of CVE-2022-43932 is high with a CVSS score of 7.5.
3
What is the affected software for CVE-2022-43932?
The affected software for CVE-2022-43932 is Synology Router Manager (SRM) versions before 1.2.5-8227-6 and 1.3.1-9346-3.
4
How can remote attackers exploit CVE-2022-43932?
Remote attackers can exploit CVE-2022-43932 by using unspecified vectors to read arbitrary files.
5
Is there a patch available for CVE-2022-43932?
Yes, a patch is available. For more information, please refer to the advisory by Synology.