CVE-2021-29087

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 22

Summary

CVE-2021-29087 is a path traversal vulnerability affecting the webapi component in Synology DiskStation Manager (DSM) prior to version 6.2.3-25426-3. This issue allows remote attackers to write arbitrary files by bypassing restrictions on directory paths. The exact vectors of attack are unspecified, making it a potential threat to Synology users who have not yet applied the necessary patch. Successful exploitation could lead to significant data compromise. It is strongly recommended that Synology users update their DSM software to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology