Lucene search

K
cvelistSynologyCVELIST:CVE-2022-27618
HistoryAug 03, 2022 - 2:20 a.m.

CVE-2022-27618

2022-08-0302:20:13
CWE-22
synology
www.cve.org
3
synology storage analyzer
path traversal
remote authenticated users
file deletion

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

26.5%

Improper limitation of a pathname to a restricted directory (‘Path Traversal’) vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.

CNA Affected

[
  {
    "product": "Storage Analyzer",
    "vendor": "Synology",
    "versions": [
      {
        "lessThan": "2.1.0-0390",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

26.5%

Related for CVELIST:CVE-2022-27618