Impact
The vulnerability is an improper certificate validation flaw in DSM's Email API that allows attackers who can perform a man‑in‑the‑middle between the API client and server to read and write arbitrary files on the device. This flaw also enables denial‑of‑service by forging certificate errors to terminate API functions. The weakness aligns with CWE‑295, improper handling of security certificates.
Affected Systems
Affected products include Synology DiskStation Manager (DSM) for versions before 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any device running these releases that exposes the Email API to external networks is vulnerable. The documentation does not specify additional variant or edition, so all standard DSM distributions are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, while the EPSS score of less than 1% suggests low exploitation probability so far. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by intercepting traffic to the Email API, which requires network access to the DSM appliance and the ability to inject a rogue certificate. Consequently, the risk is noticeable for exposed systems, but the likelihood is currently low.
OpenCVE Enrichment