Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
History

Tue, 14 Jan 2025 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

Fri, 03 Jan 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 07:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors. Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

Thu, 28 Nov 2024 07:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled search path element vulnerability in Backup Management Functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to read or write arbitrary files via unspecified vectors. Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
Weaknesses CWE-427

cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2025-01-03T01:55:23.191Z

Reserved: 2023-01-10T02:14:16.029Z

Link: CVE-2023-0142

cve-icon Vulnrichment

Updated: 2024-08-02T05:02:43.739Z

cve-icon NVD

Status : Modified

Published: 2023-06-13T07:15:46.203

Modified: 2025-01-14T19:29:55.853

Link: CVE-2023-0142

cve-icon Redhat

No data.