SB2025032115 - Multiple vulnerabilities in Synology SRM
Published: March 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2025-29843)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to an unspecified vulnerability. A remote user can bypass implemented security restrictions.
2) Information disclosure (CVE-ID: CVE-2025-29844)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information.
3) Information disclosure (CVE-ID: CVE-2025-29845)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information.
4) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-29846)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions. A remote user can escalate privileges on the system.
Remediation
Install update from vendor's website.