PT-2022-6125 · Synology · Synology Vpn Plus Server

Published

2022-12-30

·

Updated

2025-09-26

·

CVE-2022-43931

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology VPN Plus Server versions prior to 1.4.3-0534 and 1.4.4-0635
Description The issue is related to an out-of-bounds write vulnerability in the Remote Desktop functionality of Synology VPN Plus Server. This vulnerability can be exploited by remote attackers to execute arbitrary commands via unspecified vectors, potentially leading to severe consequences such as data damage, system crashes, and code execution after memory corruption. It is noted that the vulnerability can be used in low-complexity attacks without privileges on the target routers or user interaction.
Recommendations For Synology VPN Plus Server versions prior to 1.4.3-0534, update to version 1.4.3-0534 or later. For Synology VPN Plus Server versions prior to 1.4.4-0635, update to version 1.4.4-0635 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00073
CVE-2022-43931

Affected Products

Synology Vpn Plus Server