Vulnerabilidades em Synology

317 resultados
Análise Vexday

Com 294 CVEs catalogadas, o histórico da Synology apresenta taxa de exploração ativa abaixo da média geral do catálogo — nenhuma vulnerabilidade consta atualmente no CISA KEV —, o que sugere superfície de risco ativo relativamente contida em comparação ao universo de fornecedores monitorados. Ainda assim, 30 falhas classificadas como críticas e 6 com prova de conceito pública representam vetores concretos de ataque que exigem atenção contínua de equipes de patch management. O CVE mais perigoso em atividade, CVE-2017-15889, registra EPSS de 0,7245, indicando alta probabilidade estimada de exploração — sua antiguidade não reduz o risco, e ambientes que ainda não aplicaram a correção devem tratá-lo como prioridade imediata. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), somado às 25 CVEs surgidas nos últimos 90 dias, reforça a necessidade de ciclos de remediação regulares e monitoramento ativo de novas divulgações.

CVE-2017-11149Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 EPSS 1.6%CVE-2022-22688HIGHImproper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology EPSS 1.6%CVE-2022-27624CRITICALA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionEPSS 1.6%CVE-2022-27625CRITICALA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functioEPSS 1.6%CVE-2022-22684HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in SynEPSS 1.6%CVE-2024-39351HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP conEPSS 1.5%CVE-2023-41738HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality iEPSS 1.5%CVE-2023-32956CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology RouterEPSS 1.5%CVE-2022-27610MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation ManEPSS 1.5%CVE-2021-26566HIGHInsertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allEPSS 1.5%CVE-2018-13297MEDIUMInformation exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitEPSS 1.5%CVE-2018-13288MEDIUMInformation exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remoteEPSS 1.5%CVE-2023-47802HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP blocEPSS 1.5%CVE-2022-27620MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server befoEPSS 1.5%CVE-2024-10442CRITICALOff-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 aEPSS 1.4%CVE-2017-12080An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allEPSS 1.4%CVE-2024-39349CRITICALA vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and itEPSS 1.4%CVE-2018-8919HIGHInformation exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote aEPSS 1.4%CVE-2017-11148Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to accEPSS 1.4%CVE-2021-29087HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation ManEPSS 1.4%