Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-11156


Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.


Published

2017-08-14T19:29:01.147

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-276
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology download_station 3.2-2295 Yes
Application synology download_station 3.3-2382 Yes
Application synology download_station 3.3-2383 Yes
Application synology download_station 3.3-2386 Yes
Application synology download_station 3.4-2477 Yes
Application synology download_station 3.4-2478 Yes
Application synology download_station 3.4-2480 Yes
Application synology download_station 3.4-2485 Yes
Application synology download_station 3.4-2486 Yes
Application synology download_station 3.4-2489 Yes
Application synology download_station 3.4-2490 Yes
Application synology download_station 3.4-2514 Yes
Application synology download_station 3.4-2555 Yes
Application synology download_station 3.4-2557 Yes
Application synology download_station 3.4-2558 Yes
Application synology download_station 3.5-2638 Yes
Application synology download_station 3.5-2705 Yes
Application synology download_station 3.5-2706 Yes
Application synology download_station 3.5-2955 Yes
Application synology download_station 3.5-2956 Yes
Application synology download_station 3.5-2962 Yes
Application synology download_station 3.5-2963 Yes
Application synology download_station 3.5-2967 Yes
Application synology download_station 3.5-2968 Yes
Application synology download_station 3.5-2970 Yes
Application synology download_station 3.5-2973 Yes
Application synology download_station 3.5-2980 Yes
Application synology download_station 3.5-2982 Yes
Application synology download_station 3.8.0-3416 Yes
Application synology download_station 3.8.1-3420 Yes
Application synology download_station 3.8.2-3455 Yes
Application synology download_station 3.8.3-3458 Yes
Application synology download_station 3.8.4-3468 Yes

References