Lucene search

K
cveSynologyCVE-2022-43932
HistoryJan 05, 2023 - 10:15 a.m.

CVE-2022-43932

2023-01-0510:15:09
synology
web.nvd.nist.gov
32
cve-2022-43932
injection
synology router manager
srm
security vulnerability
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

32.6%

Improper neutralization of special elements in output used by a downstream component (‘Injection’) vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.

Affected configurations

Nvd
Node
synologyrouter_managerRange1.21.2.5-8227-6
OR
synologyrouter_managerRange1.31.3.1-9346-3
VendorProductVersionCPE
synologyrouter_manager*cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Synology",
    "product": "Synology Router Manager (SRM)",
    "versions": [
      {
        "version": "1.2",
        "status": "affected",
        "lessThan": "1.2.5-8227-6",
        "versionType": "semver"
      },
      {
        "version": "1.3",
        "status": "affected",
        "lessThan": "1.3.1-9346-3",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "affected"
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

32.6%

Related for CVE-2022-43932