CVE-2023-0142 - CVE House
Back to Database
Status published Medium CVE-2023-0142

Uncontrolled search path element vulnerability in Backup Management functionality in...

Vulnerability Description

Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-0142

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Chanyoung So

Affected Vendor

Affected Software

DiskStation Manager (DSM), Unified Controller (DSMUC), Synology Router Manager (SRM)
Vulnerable Versions:
7.2, 7.1, 7.0, 6.2, 0, 3.1, 1.3, 1.2

Timeline

Official Publish: June 13th, 2023
Last Modified: January 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)