CVE-2015-2851
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
30/05/2015
Last modified:
12/04/2025
Description
client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:synology:cloud_station:1.1-2291:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:2.0-2291:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:2.0-2402:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:2.1-2561:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:2.1-2570:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:2.1-2577:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.0-3005:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.0-3103:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.0-3108:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.0-3109:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.0-3111:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.1-3317:*:*:*:*:*:*:* | ||
| cpe:2.3:a:synology:cloud_station:3.1-3320:*:*:*:*:*:*:* | ||
| cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



