CVE-2015-2851 describes a local privilege escalation vulnerability in Synology Cloud Station versions 1.1-2291 through 3.1-3320 on macOS. An authenticated local user can exploit a flaw in the client_chown function to change the ownership of arbitrary files, leading to root access. This vulnerability has a CVSS score of 6.8, indicating high severity with low attack complexity and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1-2291CPE matchmatch criteria | cpe:2.3:a:synology:cloud_station:1.1-2291:*:*:*:*:*:*:* | ||
2.0-2291CPE matchmatch criteria | cpe:2.3:a:synology:cloud_station:2.0-2291:*:*:*:*:*:*:* | ||
2.0-2402CPE matchmatch criteria | cpe:2.3:a:synology:cloud_station:2.0-2402:*:*:*:*:*:*:* | ||
2.1-2561CPE matchmatch criteria | cpe:2.3:a:synology:cloud_station:2.1-2561:*:*:*:*:*:*:* | ||
2.1-2570CPE matchmatch criteria | cpe:2.3:a:synology:cloud_station:2.1-2570:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.