CVE-2022-49036: High severity Synology Active Backup for Business Recovery Media Creator vulnerability
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology Active Backup for Business Recovery Media Creatorto a version that resolves this vulnerability.Fixed in 2.5.0-2081
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49036?
CVE-2022-49036 has a high severity rating of 7.8.
How does CVE-2022-49036 affect users?
CVE-2022-49036 allows local users to execute arbitrary code, posing significant security risks.
What systems are impacted by CVE-2022-49036?
CVE-2022-49036 affects Synology Active Backup for Business Recovery Media Creator versions prior to 2.5.0-2081.
How do I fix CVE-2022-49036?
To fix CVE-2022-49036, users should upgrade to Synology Active Backup for Business Recovery Media Creator version 2.5.0-2081 or later.
What type of vulnerability is CVE-2022-49036?
CVE-2022-49036 is classified as an inclusion of functionality from an untrusted control sphere vulnerability.