PT-2022-27021 · Synology · Synology Presto File Server

Cq674350529

+1

·

Published

2022-10-26

·

Updated

2022-10-28

·

CVE-2022-43749

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Presto File Server versions prior to 2.1.2-1601
Description The issue is related to improper privilege management in the summary report management of Synology Presto File Server. This allows remote authenticated users to bypass security constraints.
Recommendations For versions prior to 2.1.2-1601, update to version 2.1.2-1601 or later to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-43749

Affected Products

Synology Presto File Server