Synology Vulnerabilities and Affected Products
Vulnerabilities associated with Synology Photo Station.
Products
Clear product- DiskStation Manager (DSM)53 vulnerabilities
- Synology Router Manager (SRM)43 vulnerabilities
- Surveillance Station25 vulnerabilities
- Synology Photo Station18 vulnerabilities
- Synology DiskStation Manager (DSM)13 vulnerabilities
- Photo Station12 vulnerabilities
- Camera Firmware9 vulnerabilities
- Drive7 vulnerabilities
- BeeDrive for desktop6 vulnerabilities
- Calendar6 vulnerabilities
- camera_firmware6 vulnerabilities
- router_manager6 vulnerabilities
- Synology Drive Client6 vulnerabilities
- Unified Controller (DSMUC)6 vulnerabilities
- Media Server5 vulnerabilities
- Synology Active Backup for Business Agent5 vulnerabilities
- Synology Calendar5 vulnerabilities
- Active Backup for Business4 vulnerabilities
- Note Station4 vulnerabilities
- active_backup_for_business_agent3 vulnerabilities
- Audio Station3 vulnerabilities
- BeeStation OS (BSM)3 vulnerabilities
- Download Station3 vulnerabilities
- Safe Access3 vulnerabilities
- Synology Download Station3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-29089CRITICAL | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors. CWE-89Jun 2, 2021 | CVSS9.8v3.1 | EPSS1.93% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-29090HIGH | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors. CWE-89Jun 2, 2021 | CVSS7.2v3.1 | EPSS1.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-29091HIGH | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors. CWE-22Jun 2, 2021 | CVSS7.7v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-29092HIGH | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors. CWE-434Jun 1, 2021 | CVSS8.8v3.1 | EPSS1.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-16769MEDIUM | Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. | CVSS5.3v3.0 | EPSS1.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11162MEDIUM | Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors. CWE-22Sep 8, 2017 | CVSS6.5v3.0 | EPSS1.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-12071MEDIUM | Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter. CWE-918Sep 8, 2017 | CVSS6.5v3.0 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11161CRITICAL | Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php. CWE-89Sep 8, 2017 | CVSS9.8v3.0 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-9555MEDIUM | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter. CWE-79Aug 24, 2017 | CVSS5.4v3.0 | EPSS0.794% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11151CRITICAL | Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code ExecutionA vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action. CWE-287Aug 8, 2017 | CVSS9.8v3.0 | EPSS16.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11155HIGH | Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code ExecutionAn information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors. | CVSS7.5v3.0 | EPSS47.4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11153CRITICAL | Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code ExecutionDeserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload. CWE-502Aug 8, 2017 | CVSS9.8v3.0 | EPSS12.2% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11154HIGH | Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code ExecutionUnrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter. CWE-434Aug 8, 2017 | CVSS7.2v3.0 | EPSS8.63% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-11152HIGH | Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code ExecutionDirectory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter. CWE-22Aug 8, 2017 | CVSS7.5v3.0 | EPSS14.6% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-9552HIGH | A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline". | CVSS7.8v3.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-10329CRITICAL | Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header. CWE-77May 12, 2017 | CVSS9.8v3.0 | EPSS40.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-10330HIGH | Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors. | CVSS7.1v3.0 | EPSS0.693% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-10331HIGH | Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter. CWE-22May 12, 2017 | CVSS7.5v3.0 | EPSS2.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |