CVE-2022-3576

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 20, 2022
Updated: Jan 14, 2025

Summary

CVE-2022-3576 is a newly discovered vulnerability that impacts the session processing functionality of Out-of-Band (OOB) Management in Synology DiskStations. This issue permits remote attackers to carry out out-of-bounds reads, resulting in the leaking of sensitive information. Affected Synology models include the DS3622xs+, FS3410, and HD6500, all of which run Synology DiskStation Manager (DSM) versions prior to 7.1.1-42962-2. Successful exploitation of this vulnerability may lead to serious data breaches. Users are advised to update their DSM versions as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 7
  • Microsoft Windows Server 2008
  • Microsoft Windows 10
  • Microsoft Windows Server 2012
  • Microsoft Windows 8.1

Affected Vendors

  • Microsoft