Summary
Security updates address a vulnerability in Synology’s Media Server for DSM (DiskStation Manager) software, an application for turning your NAS device into a media server.
Risk
Community Impact Estimation for Vulnerability: Medium (63.46)
Type
- Arbitrary File Read
Affected Products and Versions
Synology
- Media Server for DSM 7.2.x, prior to 2.2.0-3325
- Media Server for DSM 7.1.x, prior to 2.0.5-3152
- Media Server for SRM 1.3.x, prior to 1.4-2680
Mitigation Actions
In line with vendor statements, it is recommended to update vulnerable products as indicated in the security bulletins listed in the References section.
References
https://www.synology.com/fr-fr/security/advisory/Synology_SA_24_28
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.