High severity7.5NVD Advisory· Published Jun 23, 2021· Updated Jun 17, 2026
CVE-2021-29084
CVE-2021-29084
Description
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4unspecified+ 2 more
- (no CPE)range: unspecified
- cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=6.2,<6.2.3-25426-3
- (no CPE)range: <6.2.3-25426-3
- cpe:2.3:o:synology:diskstation_manager_unified_controller:*:*:*:*:*:*:*:*Range: <3.1-23033
Patches
Vulnerability mechanics
References
1- www.synology.com/security/advisory/Synology_SA_20_26nvdVendor Advisory
News mentions
0No linked articles in our index yet.