CVE-2021-29084

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 74

Summary

CVE-2021-29084 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue involves improper neutralization of special elements in output, which can be exploited by remote attackers to read arbitrary files through unspecified vectors in the Security Advisor report management component. The vulnerability, classified as an Injection type, may expose sensitive data and pose a significant risk if not addressed promptly. Users are advised to update their DSM software as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology