Impact
An improper encoding or escaping flaw in SCGI within Synology DiskStation Manager allows attackers to manipulate responses that result in arbitrary file reads or writes. By exploiting this weakness, unauthorized remote users can access sensitive files or modify system files, leading to confidentiality or integrity violations, and can trigger denial‑of‑service attacks by disrupting the SCGI service.
Affected Systems
Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075 are affected. Firmware upgrades to the listed versions or later mitigate the vulnerability.
Risk and Exploitability
With a CVSS score of 9.8, the flaw is considered critical. The EPSS score below 1 % indicates a low overall likelihood of exploitation in the near term, and it is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely by sending crafted SCGI requests to the DSM instance. The ability to read or write arbitrary files presents a high risk to confidentiality, integrity, and availability, even though exploitation attempts are currently infrequent.
OpenCVE Enrichment