Drive Client
Vendor:
First CVE: Sep 26, 2024 · Active for 1 year
6
Total CVEs
More Total CVEs than 80% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Drive Client over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2024
21 months ago
Most Recent CVE
Sep 26, 2024
668 days ago
CVE Severity & Scoring
Drive Client6 CVEs
67%
33%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (33.3%)
High3 (50.0%)
None1 (16.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52946HIGH Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to | Sep 26, 2024 | 8.2 | 23 | NO | NO |
CVE-2022-49038HIGH Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary | Sep 26, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-49037MEDIUM Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote authenticated users to obtain s | Sep 26, 2024 | 6.5 | 18 | NO | NO |
CVE-2022-49039MEDIUM Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to execute ar | Sep 26, 2024 | 6.7 | 17 | NO | NO |
CVE-2022-49041MEDIUM Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows loca | Sep 26, 2024 | 4.4 | 15 | NO | NO |
CVE-2022-49040MEDIUM Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local | Sep 26, 2024 | 4.4 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Drive Client
Top CWEs
Versions
No cataloged versions.