Taipei, Taiwan—February 14, 2014—Synology® confirmed known security issues (reported as CVE-2013-6955 and CVE-2013-6987) which would cause compromise to file access authority in DSM. An updated DSM version resolving these issues has been released accordingly.
The followings are possible symptoms to appear on affected DiskStation and RackStation:
If users identify any of above situation, they are strongly encouraged to do the following:
For other users who haven’t encountered above symptoms, it is recommended to go to DSM > Control Panel > DSM Update page, update to versions above to protect DiskStation from malicious attacks.
Synology has taken immediate actions to fix vulnerability at the point of identifying malicious attacks. As the proliferation of cybercrime and increasingly sophisticated malware evolves, Synology continues to devote resources to mitigate threats and is dedicated to providing the most reliable solutions for users. If users still notice their DiskStation behaving suspiciously after being upgraded to the latest DSM version, please contact security@synology.com.
Synology creates network attached storage and IP surveillance solutions that transform the way users manage data and conduct surveillance in the cloud era. By taking full advantage of the latest technologies, Synology aims to help users centralize data storage and backup, share files on-the-go, and implement professional surveillance solutions in reliable and affordable ways. Synology is committed to delivering products with forward-thinking features and the best in class customer services.