CVE-2018-13284

EUVD-2018-5232
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
synologyCNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
synologydiskstation_manager
5.2 ≤
𝑥
< 5.2-5967-8
synologydiskstation_manager
6.0 ≤
𝑥
< 6.0.3-8754-8
synologydiskstation_manager
6.1 ≤
𝑥
< 6.1.7-15284-1
synologydiskstation_manager
6.2 ≤
𝑥
< 6.2-23739-1
𝑥
= Vulnerable software versions