CVE-2018-13284

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Apr 1, 2019
Updated: Jan 14, 2025
CWE ID 78

Summary

CVE-2018-13284 is a command injection vulnerability affecting the ftpd service in Synology Diskstation Manager (DSM) prior to version 6.2-23739-1. This issue grants remote authenticated users the ability to execute arbitrary OS commands through the use of the MKD (Mkdir) or RMD (Rmdir) commands. By exploiting this vulnerability, an attacker can potentially gain unauthorized system access and compromise the affected Synology Diskstation. This security flaw may result in significant data loss or system damage. It is highly recommended that Synology DSM users upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology