HTTP: Synology DiskStation Manager Command Injection
This signature detects attempts to exploit a known vulnerability against Synology DiskStation Manager. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Affected Products
Synology diskstation_manager
References
CVE: CVE-2017-15889
URL: https://www.synology.com/en-global/support/security/Synology_SA_17_65_DSM
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Synology
6.5