CVE-2021-33182

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jun 1, 2021
Updated: Jan 14, 2025
CWE ID 22

Summary

CVE-2021-33182 is a path traversal vulnerability affecting the PDF Viewer component in Synology DiskStation Manager (DSM) versions prior to 6.2.4-25553. This issue permits remote, authenticated users to access limited files by traversing beyond the intended directory. The specific vectors of attack are unspecified, adding to the potential severity of this vulnerability. Successful exploitation could result in unauthorized file reading, potentially leading to sensitive data exposure. It is essential for Synology users to update their DSM installations to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology