Publish Time: 2022-10-27 13:44:08 UTC+8
Last Updated: 2023-05-22 15:32:29 UTC+8
Abstract
CVE-2022-3437 allows remote authenticated users to conduct denial-of-service attacks via a susceptible version of Synology DiskStation Manager (DSM), SMB Service and Synology Directory Server.
None of Synology's products are affected by CVE-2022-3592 as this vulnerability only affect Samba 4.17 and later.
Affected Products
Product | Severity | Fixed Release Availability |
---|---|---|
DSM 6.2 | Moderate | Will not fix |
DSMUC 3.1 | Not affected | N/A |
SRM 1.3 | Not affected | N/A |
SRM 1.2 | Not affected | N/A |
VS Firmware 2.3 | Not affected | N/A |
VS Firmware 3.0 | Not affected | N/A |
SMB Service for DSM 7.2 | Moderate | Upgrade to 4.15.13-0781 or above. |
SMB Service for DSM 7.1 | Moderate | Will not fix |
SMB Service for DSM 7.0 | Moderate | Will not fix |
Synology Directory Server for DSM 7.2 | Moderate | Upgrade to 4.15.13-0615 or above. |
Synology Directory Server for DSM 7.1 | Moderate | Will not fix |
Synology Directory Server for DSM 7.0 | Moderate | Will not fix |
Synology Directory Server for DSM 6.2 | Moderate | Will not fix |
Mitigation
None
Detail
CVE-2022-3437
CVE-2022-3592
Reference
Revision
Revision | Date | Description |
---|---|---|
1 | 2022-10-27 | Initial public release. |
2 | 2023-05-22 | Update for Synology Directory Server is now available in Affected Products. |
3 | 2023-05-22 | Update for SMB Service is now available in Affected Products. |