Product:

Diskstation_manager_unified_controller

(Synology)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 17
Date Id Summary Products Score Patch Annotated
2021-06-23 CVE-2021-27649 Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 9.8
2021-06-23 CVE-2021-29084 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 7.5
2021-06-23 CVE-2021-29085 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 7.5
2021-06-23 CVE-2021-29086 Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 7.5
2021-06-23 CVE-2021-29087 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 7.5
2022-03-25 CVE-2022-22687 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller 9.8
2023-06-13 CVE-2023-2729 Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors. Diskstation_manager, Diskstation_manager_unified_controller, Router_manager 7.5