CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:synology:diskstation_manager_unified_controller:3.1:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_1:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_2:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_3:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_4:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_5:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*

History

14 Jan 2025, 19:29

Type Values Removed Values Added
CWE CWE-427
CPE cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

03 Dec 2024, 08:15

Type Values Removed Values Added
CWE CWE-427
Summary Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors. Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

28 Nov 2024, 07:15

Type Values Removed Values Added
CWE CWE-427
References (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - Vendor Advisory () https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - Vendor Advisory
References (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - Vendor Advisory () https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - Vendor Advisory
Summary Uncontrolled search path element vulnerability in Backup Management Functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to read or write arbitrary files via unspecified vectors. Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

07 Nov 2023, 03:59

Type Values Removed Values Added
CWE CWE-427

21 Jun 2023, 16:59

Type Values Removed Values Added
First Time Synology diskstation Manager Unified Controller
Synology router Manager
Synology diskstation Manager
Synology
References (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - Vendor Advisory
References (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - (MISC) https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:a:synology:router_manager:1.3.1-9346:update_1:*:*:*:*:*:*
cpe:2.3:a:synology:diskstation_manager_unified_controller:3.1:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_5:*:*:*:*:*:*
cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_4:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_3:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_2:*:*:*:*:*:*

13 Jun 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 07:15

Updated : 2025-01-14 19:29


NVD link : CVE-2023-0142

Mitre link : CVE-2023-0142


JSON object : View

Products Affected

synology

  • diskstation_manager
  • router_manager
  • diskstation_manager_unified_controller
CWE
CWE-427

Uncontrolled Search Path Element