VYPR

Presto File Server

by Synology

CVEs (2)

  • CVE-2022-43748MedOct 26, 2022
    risk 0.38cvss 5.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.

  • CVE-2022-43749MedOct 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated users to bypass security constraint via unspecified vectors.