Vulnerability Details CVE-2017-15889
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.639
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2017-15889
-
cpe:2.3:o:synology:diskstation_manager:-
-
cpe:2.3:o:synology:diskstation_manager:3.0
-
cpe:2.3:o:synology:diskstation_manager:4.0
-
cpe:2.3:o:synology:diskstation_manager:4.0-2259
-
cpe:2.3:o:synology:diskstation_manager:4.2
-
cpe:2.3:o:synology:diskstation_manager:4.2-3243
-
cpe:2.3:o:synology:diskstation_manager:4.3
-
cpe:2.3:o:synology:diskstation_manager:4.3-3810
-
cpe:2.3:o:synology:diskstation_manager:5.2
-
cpe:2.3:o:synology:diskstation_manager:5.2-5565
-
cpe:2.3:o:synology:diskstation_manager:5.2-5565-1
-
cpe:2.3:o:synology:diskstation_manager:5.2-5565-2
-
cpe:2.3:o:synology:diskstation_manager:5.2-5592
-
cpe:2.3:o:synology:diskstation_manager:5.2-5592-1
-
cpe:2.3:o:synology:diskstation_manager:5.2-5592-2
-
cpe:2.3:o:synology:diskstation_manager:5.2-5592-3
-
cpe:2.3:o:synology:diskstation_manager:5.2-5592-4
-
cpe:2.3:o:synology:diskstation_manager:5.2-5620
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644-1
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644-2
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644-3
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644-5
-
cpe:2.3:o:synology:diskstation_manager:5.2-5644-8
-
cpe:2.3:o:synology:diskstation_manager:5.2-5967
-
cpe:2.3:o:synology:diskstation_manager:5.2-5967-1
-
cpe:2.3:o:synology:diskstation_manager:5.2-5967-2
-
cpe:2.3:o:synology:diskstation_manager:5.2-5967-3
-
cpe:2.3:o:synology:diskstation_manager:5.2-5967-4