CVE-2024-0854: Medium severity synology photos diskstation manager vulnerability
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0854?
CVE-2024-0854 is considered a high severity vulnerability due to its potential for facilitating phishing attacks.
How do I fix CVE-2024-0854?
To address CVE-2024-0854, update Synology DiskStation Manager to version 6.2.4-25556-8, or any of the subsequent fixed versions.
Who is affected by CVE-2024-0854?
CVE-2024-0854 affects remote authenticated users of Synology DiskStation Manager versions prior to 7.2.1-69057-2.
What type of attack does CVE-2024-0854 enable?
CVE-2024-0854 enables remote authenticated users to conduct phishing attacks via URL redirection to untrusted sites.
When was CVE-2024-0854 discovered?
CVE-2024-0854 was discovered impacting versions of Synology DiskStation Manager prior to 7.2.1-69057-2.