CVE-2021-43925
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 7, 2022
Updated: Jan 14, 2025
CWE ID 89
Summary
CVE-2021-43925 is a vulnerability affecting the Log Management functionality in Synology DiskStation Manager (DSM) before version 7.0.1-42218-2. This issue results from improper handling of SQL command elements, leading to SQL Injection vulnerabilities. Unspecified attack vectors can be exploited to inject malicious SQL commands, potentially granting attackers unauthorized access to sensitive data or enabling other malicious activities. Users are urged to update their DSM software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology