← back
CVE-2019-11829highobserved exploitationCWE-78

CVE-2019-11829

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.3epss 2.2%
from disclosure to weapon
Published on NVDJun 30
VulnCheck+1907d
exploitation probability
2.2%top 18% of all CVEs
observed exploitation
yesVulnCheck
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Synology · Calendar