← Back

CVE-2017-11149

nvd nist
Published: Aug 14, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

Affected (33)

1 product
Download Station
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Synology
Version 3.2-2295
Version 3.3-2382
Version 3.3-2383
Version 3.3-2386
Version 3.4-2477
Version 3.4-2478
Version 3.4-2480
Version 3.4-2485
Version 3.4-2486
Version 3.4-2489
Version 3.4-2490
Version 3.4-2514
Version 3.4-2555
Version 3.4-2557
Version 3.4-2558
Version 3.5-2638
Version 3.5-2705
Version 3.5-2706
Version 3.5-2955
Version 3.5-2956
Version 3.5-2962
Version 3.5-2963
Version 3.5-2967
Version 3.5-2968
Version 3.5-2970
Version 3.5-2973
Version 3.5-2980
Version 3.5-2982
Version 3.8.0-3416
Version 3.8.1-3420
Version 3.8.2-3455
Version 3.8.3-3458
Version 3.8.4-3468

References (2)

Timeline

No history available yet.