Synology-SA-17:65 DSM

Publish Time: 2017-11-08 17:11:36 UTC+8

Last Updated: 2017-12-04 10:34:52 UTC+8

Severity
Important
Status
Resolved

Abstract

CVE-2017-15889 allows remote authenticated users to execute arbitrary commands on a vulnerable version of Synology DiskStation Manager (DSM).

Severity

Affected

  • Products

    • DSM 5.2
  • Models

    • All Synology models

Description

Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.

Mitigation

None

Update Availability

To fix the security issue, please update DSM 5.2 to 5.2-5967-5 or above.