CVE-2024-0854: URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before...

5.4 CVSS

Description

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors.

Classification

CVE ID: CVE-2024-0854

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.4

Affected Products

Vendor: Synology

Product: DiskStation Manager (DSM)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 25.85% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.synology.com/en-global/security/advisory/Synology_SA_24_02

Timeline