4
CVSSv2

CVE-2017-11149

Published: 14/08/2017 Updated: 09/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x prior to 3.8.5-3475 and 3.x prior to 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synology download station 3.4-2480

synology download station 3.4-2485

synology download station 3.4-2486

synology download station 3.4-2489

synology download station 3.5-2706

synology download station 3.5-2955

synology download station 3.5-2956

synology download station 3.5-2962

synology download station 3.3-2382

synology download station 3.3-2386

synology download station 3.4-2478

synology download station 3.4-2490

synology download station 3.4-2555

synology download station 3.4-2558

synology download station 3.5-2705

synology download station 3.5-2963

synology download station 3.5-2968

synology download station 3.5-2973

synology download station 3.2-2295

synology download station 3.8.2-3455

synology download station 3.8.3-3458

synology download station 3.8.1-3420

synology download station 3.8.0-3416

synology download station 3.5-2980

synology download station 3.5-2982

synology download station 3.3-2383

synology download station 3.4-2477

synology download station 3.4-2514

synology download station 3.8.4-3468

synology download station 3.4-2557

synology download station 3.5-2638

synology download station 3.5-2967

synology download station 3.5-2970