Impact
The flaw is an integer overflow or wraparound within the file operation component of Synology DiskStation Manager. When a remote user who is already authenticated submits a specially crafted request, the overflow allows the device to miscalculate a file size or counter and ultimately crash its file service. This results in a limited denial‑of‑service for the affected system. The weakness is identified as CWE‑190, indicating an arithmetic overflow flaw. The impact is confined to availability, not confidentiality or integrity.
Affected Systems
Synology DiskStation Manager is affected in all releases before 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any Synology device running these versions of DSM is vulnerable, regardless of operating system or firmware other than the documented versions.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely attack requires the attacker to have valid authenticated access to the DSM environment, after which the attack can be carried out with a single HTTP request to trigger the overflow. The impact is limited to a temporary service interruption and does not grant further privileges or data access.
OpenCVE Enrichment