vendor:
Photo Station
by:
Securiteam
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Photo Station
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: a:synology:photo_station
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2018
Remote Code Execution in Synology Photo Station
The remote code execution is a combination of 4 different vulnerabilities: Upload arbitrary files to the specified directories, Log in with a fake authentication mechanism, Log in to Photo Station with any identity, Execute arbitrary code by authenticated user with administrator privileges. The chain of vulnerabilities will allow an attacker to execute code as uid=138862(PhotoStation) gid=138862(PhotoStation) groups=138862(PhotoStation).
Mitigation:
The user should ensure that the Photo Station is updated to the latest version and should also ensure that the authentication mechanism is secure.