CVE-2022-27625

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 20, 2022
Updated: Jan 14, 2025
CWE ID 119

Summary

CVE-2022-27625 is a vulnerability affecting Synology DiskStations running outdated versions of Synology DiskStation Manager (DSM). The issue lies in the message processing functionality of Out-of-Band (OOB) Management, which fails to properly restrict operations within memory buffers. Consequently, remote attackers can exploit this weakness to execute arbitrary commands. The following models are at risk: DS3622xs+, FS3410, and HD6500. Users are advised to update their DSM versions to the recommended release (7.1.1-42962-2) as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology