CVE-2023-0142

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
13/06/2023
Last modified:
14/01/2025

Description

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:synology:diskstation_manager_unified_controller:3.1:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:* 1.2 (including) 1.3.1-9346 (excluding)
cpe:2.3:a:synology:router_manager:1.3.1-9346:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_1:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_2:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_3:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_4:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_5:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.2 (including) 7.1-42661 (excluding)