Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
History

Wed, 04 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 07:15:00 +0000

Type Values Removed Values Added
Description Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published: 2024-12-04T06:59:56.673Z

Updated: 2024-12-04T14:09:11.756Z

Reserved: 2024-11-19T03:51:29.578Z

Link: CVE-2024-11398

cve-icon Vulnrichment

Updated: 2024-12-04T14:05:25.399Z

cve-icon NVD

Status : Received

Published: 2024-12-04T07:15:05.983

Modified: 2024-12-04T07:15:05.983

Link: CVE-2024-11398

cve-icon Redhat

No data.