CVE-2021-43928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
07/02/2022
Last modified:
13/05/2022

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in Synology Mail Station before 20211105-10315 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:synology:mail_station:*:*:*:*:*:*:*:* 20211105 (excluding)


References to Advisories, Solutions, and Tools