// For flags

CVE-2015-2851

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.

client_chown en el cliente sync en Synology Cloud Station 1.1-2291 hasta 3.1-3320 en OS X permite a usuarios locales cambiar la titularidad de ficheros arbitrarios, y como consecuencias obtener el acceso root, mediante la especificación de un nombre de fichero.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-04-03 CVE Reserved
  • 2015-05-30 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
1.1-2291
Search vendor "Synology" for product "Cloud Station" and version "1.1-2291"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
2.0-2291
Search vendor "Synology" for product "Cloud Station" and version "2.0-2291"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
2.0-2402
Search vendor "Synology" for product "Cloud Station" and version "2.0-2402"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
2.1-2561
Search vendor "Synology" for product "Cloud Station" and version "2.1-2561"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
2.1-2570
Search vendor "Synology" for product "Cloud Station" and version "2.1-2570"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
2.1-2577
Search vendor "Synology" for product "Cloud Station" and version "2.1-2577"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.0-3005
Search vendor "Synology" for product "Cloud Station" and version "3.0-3005"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.0-3103
Search vendor "Synology" for product "Cloud Station" and version "3.0-3103"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.0-3108
Search vendor "Synology" for product "Cloud Station" and version "3.0-3108"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.0-3109
Search vendor "Synology" for product "Cloud Station" and version "3.0-3109"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.0-3111
Search vendor "Synology" for product "Cloud Station" and version "3.0-3111"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.1-3317
Search vendor "Synology" for product "Cloud Station" and version "3.1-3317"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe
Synology
Search vendor "Synology"
Cloud Station
Search vendor "Synology" for product "Cloud Station"
3.1-3320
Search vendor "Synology" for product "Cloud Station" and version "3.1-3320"
-
Affected
in Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
*-
Safe