Impact
An attacker able to interact with the Desktop API in Synology DiskStation Manager may retrieve non‑sensitive internal data. The vulnerability, known as an exposure of sensitive information through data queries, can allow a remote attacker to obtain information that is not explicitly protected but is still valuable. The impact is limited to confidentiality; there is no direct mention of integrity or availability effects.
Affected Systems
Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2 are affected. All supported DSM releases with these version numbers before the listed updates are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level, and the EPSS of less than 1% shows that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, further suggesting that no widespread attacks have been observed. The likely attack vector is remote network access to the Desktop API; an attacker would need network reach to the DSM device and the ability to send API queries to exploit this flaw.
OpenCVE Enrichment