A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
2022-10-20T06:15:11.857
2025-01-14T19:29:55.853
Modified
CVSSv3.1: 10.0 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | diskstation_manager | < 7.1.1-42962-2 | Yes |
| Hardware | synology | ds3622xs\+ | - | No |
| Hardware | synology | fs3410 | - | No |
| Hardware | synology | hd6500 | - | No |