CVE-2021-29087
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jun 23, 2021
Updated: Jan 14, 2025
CWE ID 22
Summary
CVE-2021-29087 is a path traversal vulnerability affecting the webapi component in Synology DiskStation Manager (DSM) prior to version 6.2.3-25426-3. This issue allows remote attackers to write arbitrary files by bypassing restrictions on directory paths. The exact vectors of attack are unspecified, making it a potential threat to Synology users who have not yet applied the necessary patch. Successful exploitation could lead to significant data compromise. It is strongly recommended that Synology users update their DSM software to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
- Synology Diskstation Manager Unified Controller
Affected Vendors
- Synology