Synology DiskStation Manager
cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*
- < 7.1.1-42962-8
- < 7.2.1-69057-7
- < 7.2.2-72806-3
A missing authorization vulnerability has been identified in the synocopy feature of Synology DiskStation Manager (DSM) versions prior to 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3. This vulnerability allows remote attackers to read arbitrary files through unspecified vectors.
Exploitation of this vulnerability allows for unauthorized reading of files on the affected system.
Users can upgrade to Synology DiskStation Manager versions 7.2.2-72806-3, 7.2.1-69057-7, or 7.1.1-42962-8 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.