CVE-2021-43925

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 7, 2022
Updated: Jan 14, 2025
CWE ID 89

Summary

CVE-2021-43925 is a vulnerability affecting the Log Management functionality in Synology DiskStation Manager (DSM) before version 7.0.1-42218-2. This issue results from improper handling of SQL command elements, leading to SQL Injection vulnerabilities. Unspecified attack vectors can be exploited to inject malicious SQL commands, potentially granting attackers unauthorized access to sensitive data or enabling other malicious activities. Users are urged to update their DSM software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology