CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:synology:diskstation_manager_unified_controller:3.1:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:*:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_1:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_2:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_3:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_4:*:*:*:*:*:*
cpe:2.3:a:synology:router_manager:1.3.1-9346:update_5:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

History

14 Jan 2025, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

03 Dec 2024, 08:15

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad del elemento de ruta de búsqueda no controlada en la funcionalidad de administración de copias de seguridad en Synology DiskStation Manager (DSM) anterior a 6.2.4-25556-8, 7.0.1-42218-7 y 7.1-42661 permite que usuarios remotos autenticados con privilegios de administrador lean o escriban archivos arbitrarios a través de vectores no especificados.
Summary (en) Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors. (en) Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

28 Nov 2024, 07:15

Type Values Removed Values Added
Summary (en) Uncontrolled search path element vulnerability in Backup Management Functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to read or write arbitrary files via unspecified vectors. (en) Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
CWE CWE-427

21 Nov 2024, 07:36

Type Values Removed Values Added
References () https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - Vendor Advisory () https://www.synology.com/en-global/security/advisory/Synology_SA_23_05 - Vendor Advisory
References () https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - Vendor Advisory () https://www.synology.com/en-global/security/advisory/Synology_SA_23_06 - Vendor Advisory
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 6.5

13 Jun 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 07:15

Updated : 2025-01-14 19:29


NVD link : CVE-2023-0142

Mitre link : CVE-2023-0142

CVE.ORG link : CVE-2023-0142


JSON object : View

Products Affected

synology

  • router_manager
  • diskstation_manager_unified_controller
  • diskstation_manager
CWE
CWE-427

Uncontrolled Search Path Element