Synology-SA-17:71 SRM
Publish Time: 2017-11-15 13:27:01 UTC+8
Last Updated: 2017-12-08 16:12:50 UTC+8
- Severity
- Important
- Status
- Resolved
Abstract
CVE-2017-15895 allows remote authenticated users to write arbitrary files via a vulnerable version of Synology Router Manager (SRM).
Severity
- Impact: Important
- CVSS3 Base Score: 7.1
- CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected
- Products
- SRM 1.1
- Models
- All Synology models
Description
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
Mitigation
None
Update Availability
To fix the security issue, please update SRM 1.1 to 1.1.5-6542-4 or above.