Diskstation Manager

Vendor:

First CVE: Dec 31, 2013 · Active for 12 years

139
Total CVEs
More Total CVEs than 99% of tracked products
10.7
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.7%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Diskstation Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2013
12 years ago
Most Recent CVE
May 27, 2026
59 days ago

CVE Severity & Scoring

Diskstation Manager139 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local10 (7.2%)
Network121 (87.1%)
Unknown6 (4.3%)
Physical0 (0.0%)
Adjacent Network2 (1.4%)
Attack Complexity
Low116 (83.5%)
High17 (12.2%)
Unknown6 (4.3%)
User Interaction
None122 (87.8%)
Unknown6 (4.3%)
Required11 (7.9%)
Privileges Required
Low53 (38.1%)
High18 (12.9%)
None62 (44.6%)
Unknown6 (4.3%)

Top CVEs

Signals from CVEs in this product scope (139 CVEs).

139 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to
Jan 9, 201410.089NOYES
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac
Dec 20, 20189.884NOYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
Dec 4, 20178.883NOYES
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspeci
Jul 24, 20175.377NOYES
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileser
Feb 21, 20228.870NONO
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea
Aug 13, 20197.565NONO

Exploit Exposure

Signals from CVEs in this product scope (139 CVEs).

CISA KEV
1 CVE
0.7% of CVEs· 96th percentile
Metasploit
5 CVEs
3.6% of CVEs· 96th percentile
Nuclei
2 CVEs
1.4% of CVEs· 96th percentile
ExploitDB
10 CVEs
7.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (139 CVEs).

Media Mentions

Signals from CVEs in this product scope (139 CVEs).

Top CNAs Publishing CVEs For Diskstation Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.3_2542618.30.8%00
6.2117.147.9%11
6.1.114.91.4%00
6.147.828.2%02
6.047.328.4%02
5.257.122.8%02
4.3-381038.433.7%02
4.3110.084.6%01
4.2110.084.6%01
4.0110.084.6%01
3.2-195514.33.3%01