2024-07-14 02:06:08 +00:00

101 lines
3.2 KiB
JSON

{
"id": "CVE-2022-22684",
"sourceIdentifier": "security@synology.com",
"published": "2022-07-28T07:15:07.743",
"lastModified": "2022-08-03T20:40:03.280",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors."
},
{
"lang": "es",
"value": "La neutralizaci\u00f3n inadecuada de los elementos especiales utilizados en un comando del sistema operativo (\"inyecci\u00f3n de comandos del sistema operativo\") es una vulnerabilidad del componente de gesti\u00f3n de tareas de Synology DiskStation Manager (DSM) anterior a la versi\u00f3n 6.2.4-25553 que permite a los usuarios remotos autenticados ejecutar comandos arbitrarios a trav\u00e9s de vectores no especificados"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
},
{
"source": "security@synology.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security@synology.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.2.4-25553",
"matchCriteriaId": "BFE49AB6-9DA4-40BA-8096-F111FC5A7696"
}
]
}
]
}
],
"references": [
{
"url": "https://www.synology.com/security/advisory/Synology_SA_21_03",
"source": "security@synology.com",
"tags": [
"Vendor Advisory"
]
}
]
}