iSCSI Management Functionality in Synology DiskStation Manager (DSM) Prior to 7.1-42661: Missing Authentication Vulnerability

iSCSI Management Functionality in Synology DiskStation Manager (DSM) Prior to 7.1-42661: Missing Authentication Vulnerability

CVE-2022-27623 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.