Vulnerability Details CVE-2018-13281
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.1%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2018-13281
-
cpe:2.3:a:synology:skynas:-
-
cpe:2.3:a:synology:vs960hd:-
-
cpe:2.3:o:synology:diskstation_manager:5.2
-
cpe:2.3:o:synology:diskstation_manager:6.0
-
cpe:2.3:o:synology:diskstation_manager:6.1
-
cpe:2.3:o:synology:diskstation_manager:6.1-15047
-
cpe:2.3:o:synology:diskstation_manager:6.1-15047-1
-
cpe:2.3:o:synology:diskstation_manager:6.1-15047-2
-
cpe:2.3:o:synology:diskstation_manager:6.1.1
-
cpe:2.3:o:synology:diskstation_manager:6.1.1-15101
-
cpe:2.3:o:synology:diskstation_manager:6.1.1-15101-1
-
cpe:2.3:o:synology:diskstation_manager:6.1.1-15101-2
-
cpe:2.3:o:synology:diskstation_manager:6.1.1-15101-3
-
cpe:2.3:o:synology:diskstation_manager:6.1.1-15101-4
-
cpe:2.3:o:synology:diskstation_manager:6.1.2-15132
-
cpe:2.3:o:synology:diskstation_manager:6.1.2-15132-1
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-1
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-3
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-4
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-5
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-6
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-7
-
cpe:2.3:o:synology:diskstation_manager:6.1.3-15152-8
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217-1
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217-2
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217-3
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217-4
-
cpe:2.3:o:synology:diskstation_manager:6.1.4-15217-5
-
cpe:2.3:o:synology:diskstation_manager:6.1.6-15266
-
cpe:2.3:o:synology:diskstation_manager:6.1.7-15284
-
cpe:2.3:o:synology:diskstation_manager:6.1.7-15284-1
-
cpe:2.3:o:synology:diskstation_manager:6.2
-
cpe:2.3:o:synology:diskstation_manager:6.2-23739
-
cpe:2.3:o:synology:diskstation_manager:6.2-23739-1