CVE-2018-13284

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
synologyCNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
synologydiskstation_manager
5.2 ≤
𝑥
< 5.2-5967-8
synologydiskstation_manager
6.0 ≤
𝑥
< 6.0.3-8754-8
synologydiskstation_manager
6.1 ≤
𝑥
< 6.1.7-15284-1
synologydiskstation_manager
6.2 ≤
𝑥
< 6.2-23739-1
𝑥
= Vulnerable software versions