Synology-SA-17:70 DSM
Publish Time: 2017-11-15 13:26:55 UTC+8
Last Updated: 2017-12-08 16:12:17 UTC+8
- Severity
- Important
- Status
- Resolved
Abstract
CVE-2017-15894 allows remote authenticated users to write arbitrary files via a vulnerable version of Synology DiskStation Manager (DSM).
Severity
- Impact: Important
- CVSS3 Base Score: 7.1
- CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected
- Products
- DSM 6.0
- DSM 5.2
- Models
- All Synology models
Description
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
Mitigation
None
Update Availability
To fix the security issue, please update DSM 6.0 to 6.0.3-8754-3 or above and DSM 5.2 to 5.2-5967-6 or above.