Input validation error in DiskStation Manager (DSM) - #VU99968
Published: November 6, 2024
Vulnerability identifier: #VU99968
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the affected device.
Affected software
DiskStation Manager (DSM)
BeeStation OS
BeeStation OS
Remediation
Install updates from vendor's website.
DiskStation Manager (DSM) - update to 7.2.2-72806-1
BeeStation OS - update to 1.1-65374
BeeStation OS - update to 1.1-65374