CVE-2021-29086
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2021-29086 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.3-25426-3. This issue permits unauthorized actors to access sensitive information through unspecified vectors in the webapi component. By exploiting this weakness, attackers can gain unauthorized access to data that is typically restricted, potentially leading to privacy breaches or further unauthorized system actions. This vulnerability poses a serious risk and requires immediate attention from Synology users to apply the necessary updates and secure their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
- Synology Diskstation Manager Unified Controller
Affected Vendors
- Synology