CVE-2021-31439
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published May 21, 2021
Updated: Jan 14, 2025
CWE ID 787
CWE ID 122
Summary
CVE-2021-31439 is a serious vulnerability affecting Synology DiskStation Manager. This issue permits network-adjacent attackers to execute arbitrary code on susceptible installations without requiring authentication. The root cause of this vulnerability lies in the improper validation of user-supplied data length before copying it to a heap-based buffer in the processing of DSI structures in Netatalk. Consequently, an attacker can exploit this flaw to run code in the current process context. (ZDI-CAN-12326)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Netatalk
- DiskStation Manager
- Debian
Affected Vendors
- Debian
- Netatalk
- Synology