CVE-2021-31439

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published May 21, 2021
Updated: Jan 14, 2025
CWE ID 787
CWE ID 122

Summary

CVE-2021-31439 is a serious vulnerability affecting Synology DiskStation Manager. This issue permits network-adjacent attackers to execute arbitrary code on susceptible installations without requiring authentication. The root cause of this vulnerability lies in the improper validation of user-supplied data length before copying it to a heap-based buffer in the processing of DSI structures in Netatalk. Consequently, an attacker can exploit this flaw to run code in the current process context. (ZDI-CAN-12326)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Netatalk
  • DiskStation Manager
  • Debian

Affected Vendors

  • Debian
  • Netatalk
  • Synology