Impact
An incorrect permission assignment in the LDAP API of Synology DiskStation Manager permits remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. The flaw allows attackers to manipulate critical system resources, potentially compromising confidentiality, integrity, and availability of the device due to improper access control.
Affected Systems
The vulnerability affects Synology DiskStation Manager versions before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Devices running any of these releases are at risk if the LDAP API is enabled.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score of less than 1% suggests a low exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access; however, once authenticated, attackers can read or modify files, which may lead to compromise or service disruption.
OpenCVE Enrichment