Jump to content
XPEnology Community

Synology Security Advisory


Nuno

Recommended Posts

Seems that all 6-2 and 7 versions are affected

 

A vulnerability allows remote authenticated users to execute arbitrary commands via a susceptible version of DiskStation Manager (DSM).https://www.synology.com/en-global/security/advisory/Synology_SA_22_03

 

Found this info on https://www.computerbase.de/2022-02/synology-nas-sicherheitsluecke-erlaubt-beliebige-code-ausfuehrung/ (german)

 

For my "real" Synology I had to manually download 6.2.4-25556-5 as it was not yet shown in interface

Edited by Nuno
info about version
Link to comment
Share on other sites

1 hour ago, Nuno said:

Seems that all 6-2 and 7 versions are affected

 

A vulnerability allows remote authenticated users to execute arbitrary commands via a susceptible version of DiskStation Manager (DSM).https://www.synology.com/en-global/security/advisory/Synology_SA_22_03

 

Found this info on https://www.computerbase.de/2022-02/synology-nas-sicherheitsluecke-erlaubt-beliebige-code-ausfuehrung/ (german)

 

For my "real" Synology I had to manually download 6.2.4-25556-5 as it was not yet shown in interface

At least the vulnerability can't be exploited without being already authenticated...

If you must expose DSM, at least use a really strong password, enable multi factor authentication. and configure ban settings.

Edited by Orphée
Link to comment
Share on other sites

  • 2 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...