Vulnerabilidades em Synology

317 resultados
Análise Vexday

Com 294 CVEs catalogadas, o histórico da Synology apresenta taxa de exploração ativa abaixo da média geral do catálogo — nenhuma vulnerabilidade consta atualmente no CISA KEV —, o que sugere superfície de risco ativo relativamente contida em comparação ao universo de fornecedores monitorados. Ainda assim, 30 falhas classificadas como críticas e 6 com prova de conceito pública representam vetores concretos de ataque que exigem atenção contínua de equipes de patch management. O CVE mais perigoso em atividade, CVE-2017-15889, registra EPSS de 0,7245, indicando alta probabilidade estimada de exploração — sua antiguidade não reduz o risco, e ambientes que ainda não aplicaram a correção devem tratá-lo como prioridade imediata. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), somado às 25 CVEs surgidas nos últimos 90 dias, reforça a necessidade de ciclos de remediação regulares e monitoramento ativo de novas divulgações.

CVE-2017-11161Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary EPSS 1.2%CVE-2023-32955HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in SynEPSS 1.2%CVE-2018-13291MEDIUMInformation exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenEPSS 1.2%CVE-2022-27615HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before EPSS 1.2%CVE-2021-29086MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.EPSS 1.2%CVE-2018-13281MEDIUMInformation exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated useEPSS 1.2%CVE-2022-22679MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskSEPSS 1.2%CVE-2024-53286HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in SynEPSS 1.1%CVE-2021-29091HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo EPSS 1.1%CVE-2022-22680MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42EPSS 1.1%CVE-2018-8913HIGHMissing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a EPSS 1.1%CVE-2021-34812MEDIUMUse of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitEPSS 1.1%CVE-2021-33182MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStationEPSS 1.1%CVE-2025-4679MEDIUMA vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecEPSS 1.1%CVE-2017-16775HIGHImproper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote atEPSS 1.1%CVE-2022-27626CRITICALA vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the sessioEPSS 1.1%CVE-2017-15888Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticatEPSS 1.1%CVE-2022-27613HIGHImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV SEPSS 1.1%CVE-2017-15891Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modiEPSS 1.0%CVE-2018-8912MEDIUMCross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated useEPSS 1.0%