Synology-SA-17:65 DSM
Publish Time: 2017-11-08 17:11:36 UTC+8
Last Updated: 2017-12-04 10:34:52 UTC+8
- Severity
- Important
- Status
- Resolved
Abstract
CVE-2017-15889 allows remote authenticated users to execute arbitrary commands on a vulnerable version of Synology DiskStation Manager (DSM).
Severity
- Impact: Important
- CVSS3 Base Score: 7.2
- CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected
Products
- DSM 5.2
Models
- All Synology models
Description
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Mitigation
None
Update Availability
To fix the security issue, please update DSM 5.2 to 5.2-5967-5 or above.