CVE-2021-43929

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 7, 2022
Updated: Jan 14, 2025
CWE ID 79
CWE ID 74

Summary

CVE-2021-43929 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 7.0.1-42218-2. This issue involves improper neutralization of special elements in output, allowing remote authenticated users to inject arbitrary web scripts or HTML through unspecified vectors in the work flow management component. This Injection vulnerability poses a significant risk, as attackers could potentially manipulate the DSM's functionality and gain unauthorized access or steal sensitive information. Users are strongly encouraged to upgrade to a patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology