Impact
Synology DiskStation Manager contains a server‑side request forgery flaw in its PersonMail API that allows any user who can authenticate to the system to execute requests to internal or external resources and retrieve response data. The vulnerability does not grant arbitrary code execution or elevated privileges, but it can expose configuration data or other non‑sensitive information that should remain private. The weakness corresponds to the Common Weakness Enumeration 918, which describes messages sent from an application to a trusted server that could be redirected or manipulated by an attacker.
Affected Systems
The flaw is present in all Synology DSM releases prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2, meaning any DSM installation older than these specific revisions is vulnerable.
Risk and Exploitability
The official CVSS score is 4.3, placing the issue in the low‑to‑moderate range. The EPSS score is below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires that the attacker already possesses valid authenticated credentials against the DSM system; once authenticated, the SSRF can be triggered from the web interface without additional inputs, making the exploitation straightforward for insiders or attackers who have compromised a user account.
OpenCVE Enrichment