CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
synologyCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
synologydiskstation_manager_unified_controller
3.1
synologyrouter_manager
1.2 ≤
𝑥
< 1.3.1-9346
synologyrouter_manager
1.3.1-9346
synologyrouter_manager
1.3.1-9346:update_1
synologyrouter_manager
1.3.1-9346:update_2
synologyrouter_manager
1.3.1-9346:update_3
synologyrouter_manager
1.3.1-9346:update_4
synologyrouter_manager
1.3.1-9346:update_5
synologydiskstation_manager
6.2 ≤
𝑥
< 7.1-42661
𝑥
= Vulnerable software versions