Vulnerabilities > CVE-2022-49038 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Synology Drive Client

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
synology
CWE-829

Summary

Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Synology
1