CVE-2021-27649

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 416

Summary

CVE-2021-27649 is a use-after-free vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue, which allows remote attackers to execute arbitrary code, exists within the file transfer protocol component of DSM. The exploitation of this vulnerability occurs due to improper memory handling, resulting in a memory location being accessed after it has been freed. This vulnerability poses a significant risk, as successful exploitation enables attackers to gain unauthorized access and potentially take control of affected systems. It is strongly recommended that users update their Synology DSM installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology