CVE-2022-22684

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jul 28, 2022
Updated: Jan 14, 2025
CWE ID 78

Summary

CVE-2022-22684 is an OS Command Injection vulnerability affecting Synology DiskStation Manager (DSM) before version 6.2.4-25553. This issue permits remote authenticated users to execute arbitrary commands by improperly neutralizing special elements in operating system commands. The task management component is the affected part of the software. The precise vectors of attack are yet to be determined.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology