ZDI-CAN-19674: ZDI-26-187: (Pwn2Own) Synology DiskStation Manager Netatalk Library Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2022-45188.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19674?
ZDI-CAN-19674 has a high severity rating due to its ability to allow remote code execution without authentication.
How do I fix ZDI-CAN-19674?
To fix ZDI-CAN-19674, update your Synology DiskStation Manager to the latest version where the vulnerability has been patched.
Which versions of Synology DiskStation Manager are affected by ZDI-CAN-19674?
All affected versions of Synology DiskStation Manager prior to the patch release contain ZDI-CAN-19674.
Can ZDI-CAN-19674 be exploited remotely?
Yes, ZDI-CAN-19674 can be exploited remotely without the need for user authentication.
What are the potential impacts of ZDI-CAN-19674?
The potential impacts of ZDI-CAN-19674 include arbitrary code execution and complete control over the affected systems.