VYPR

Cloud Station Drive

by Synology

CVEs (2)

  • CVE-2017-11158HigAug 31, 2017
    risk 0.51cvss 7.8epss 0.00

    Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or…

  • CVE-2015-2851May 30, 2015
    risk 0.00cvss epss 0.01

    client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.