CVE-2021-29084
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 74
Summary
CVE-2021-29084 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue involves improper neutralization of special elements in output, which can be exploited by remote attackers to read arbitrary files through unspecified vectors in the Security Advisor report management component. The vulnerability, classified as an Injection type, may expose sensitive data and pose a significant risk if not addressed promptly. Users are advised to update their DSM software as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
- Synology Diskstation Manager Unified Controller
Affected Vendors
- Synology