CVE-2021-27649
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2021-27649 is a use-after-free vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue, which allows remote attackers to execute arbitrary code, exists within the file transfer protocol component of DSM. The exploitation of this vulnerability occurs due to improper memory handling, resulting in a memory location being accessed after it has been freed. This vulnerability poses a significant risk, as successful exploitation enables attackers to gain unauthorized access and potentially take control of affected systems. It is strongly recommended that users update their Synology DSM installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
- Synology Diskstation Manager Unified Controller
Affected Vendors
- Synology