Security Advisory

CVE-2022-27626

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-10-20 05:50:10
Last updated 2025-05-08 13:42:27
Assigner synology
State PUBLISHED

Description

A vulnerability regarding concurrent execution using shared resource with improper synchronization (Race Condition) is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.