Vulnerabilidades em Synology

317 resultados
Análise Vexday

Com 294 CVEs catalogadas, o histórico da Synology apresenta taxa de exploração ativa abaixo da média geral do catálogo — nenhuma vulnerabilidade consta atualmente no CISA KEV —, o que sugere superfície de risco ativo relativamente contida em comparação ao universo de fornecedores monitorados. Ainda assim, 30 falhas classificadas como críticas e 6 com prova de conceito pública representam vetores concretos de ataque que exigem atenção contínua de equipes de patch management. O CVE mais perigoso em atividade, CVE-2017-15889, registra EPSS de 0,7245, indicando alta probabilidade estimada de exploração — sua antiguidade não reduz o risco, e ambientes que ainda não aplicaram a correção devem tratá-lo como prioridade imediata. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), somado às 25 CVEs surgidas nos últimos 90 dias, reforça a necessidade de ciclos de remediação regulares e monitoramento ativo de novas divulgações.

CVE-2018-13283HIGHLack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackersEPSS 1.4%CVE-2017-12071Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote aEPSS 1.4%CVE-2021-34810CRITICALImproper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated useEPSS 1.4%CVE-2018-13299MEDIUMRelative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to uplEPSS 1.4%CVE-2017-16773MEDIUMImproper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users tEPSS 1.4%CVE-2018-13287MEDIUMIncorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticateEPSS 1.3%CVE-2021-29085HIGHImproper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management EPSS 1.3%CVE-2021-29084HIGHImproper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report EPSS 1.3%CVE-2022-27618MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage AnalyzeEPSS 1.3%CVE-2020-27658HIGHSynology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makeEPSS 1.3%CVE-2018-8914HIGHSQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arEPSS 1.3%CVE-2018-13290MEDIUMInformation exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users tEPSS 1.3%CVE-2018-13292MEDIUMInformation exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticaEPSS 1.3%CVE-2018-13286MEDIUMIncorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authentiEPSS 1.3%CVE-2019-11822MEDIUMRelative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remoEPSS 1.3%CVE-2018-13295MEDIUMInformation exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authentEPSS 1.3%CVE-2018-13294MEDIUMInformation exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated usEPSS 1.3%CVE-2017-16771Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackeEPSS 1.3%CVE-2022-22685HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server bEPSS 1.2%CVE-2024-10441CRITICALImproper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and SynolEPSS 1.2%