CVE-2023-28129

Publication date

2023-08-10 19:07:44

Family

hackerone

State

PUBLISHED

Description

DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.