CVE-2017-15894

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Dec 8, 2017
Updated: Jan 14, 2025
CWE ID 22

Summary

CVE-2017-15894 is a directory traversal vulnerability affecting Synology DiskStation Manager (DSM) versions 6.0.x before 6.0.3-8754-3 and 5.2-5967-6. This issue resides within the SYNO.FileStation.Extract module. Authenticated remote users can exploit this vulnerability by manipulating the 'dest_folder_path' parameter, allowing them to write arbitrary files on the targeted system. This poses a significant risk, as it could lead to data leakage, unauthorized file modifications, or even system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology