CVE-2021-29086

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 200

Summary

CVE-2021-29086 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue permits unauthorized actors to access sensitive information through unspecified vectors in the webapi component. By exploiting this weakness, attackers can gain unauthorized access to data that is typically restricted, potentially leading to privacy breaches or further unauthorized system actions. This vulnerability poses a serious risk and requires immediate attention from Synology users to apply the necessary updates and secure their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology