vendor:
StorageManager
by:
Nigusu Kassahun
9,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: StorageManager
Affected Version From: Synology StorageManager <= 5.2
Affected Version To: Synology StorageManager <= 5.2
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Synology StorageManager <= 5.2 Remote Root Command Execution
User controlled input is not sufficiently sanitized, and then passed to execve function. Successful exploitation of this vulnerability enables a remote unauthenticated user to run commands as root on the machine. The vulnerable parameter can be found in /webman/modules/StorageManager/smart.cgi with parameter action=apply&operation=quick&disk=%2Fdev%2Fsda. Proof of Concept is an IDOR to bypass authentication and ticks to chain commands.
Mitigation:
Synology has released patches to address this vulnerability – DSM 5.2-5967-5