6.5

CVE-2017-11149

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SynologyDownload Station Version3.2-2295
SynologyDownload Station Version3.3-2382
SynologyDownload Station Version3.3-2383
SynologyDownload Station Version3.3-2386
SynologyDownload Station Version3.4-2477
SynologyDownload Station Version3.4-2478
SynologyDownload Station Version3.4-2480
SynologyDownload Station Version3.4-2485
SynologyDownload Station Version3.4-2486
SynologyDownload Station Version3.4-2489
SynologyDownload Station Version3.4-2490
SynologyDownload Station Version3.4-2514
SynologyDownload Station Version3.4-2555
SynologyDownload Station Version3.4-2557
SynologyDownload Station Version3.4-2558
SynologyDownload Station Version3.5-2638
SynologyDownload Station Version3.5-2705
SynologyDownload Station Version3.5-2706
SynologyDownload Station Version3.5-2955
SynologyDownload Station Version3.5-2956
SynologyDownload Station Version3.5-2962
SynologyDownload Station Version3.5-2963
SynologyDownload Station Version3.5-2967
SynologyDownload Station Version3.5-2968
SynologyDownload Station Version3.5-2970
SynologyDownload Station Version3.5-2973
SynologyDownload Station Version3.5-2980
SynologyDownload Station Version3.5-2982
SynologyDownload Station Version3.8.0-3416
SynologyDownload Station Version3.8.1-3420
SynologyDownload Station Version3.8.2-3455
SynologyDownload Station Version3.8.3-3458
SynologyDownload Station Version3.8.4-3468
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.487
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.