CVE-2017-11149

Summary

CVECVE-2017-11149
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2017-08-14 19:29:00 UTC
Updated2019-10-09 23:21:00 UTC
DescriptionServer-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

Risk And Classification

Problem Types: CWE-918

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Synology Download Station 3.2-2295 All All All
Application Synology Download Station 3.3-2382 All All All
Application Synology Download Station 3.3-2383 All All All
Application Synology Download Station 3.3-2386 All All All
Application Synology Download Station 3.4-2477 All All All
Application Synology Download Station 3.4-2478 All All All
Application Synology Download Station 3.4-2480 All All All
Application Synology Download Station 3.4-2485 All All All
Application Synology Download Station 3.4-2486 All All All
Application Synology Download Station 3.4-2489 All All All
Application Synology Download Station 3.4-2490 All All All
Application Synology Download Station 3.4-2514 All All All
Application Synology Download Station 3.4-2555 All All All
Application Synology Download Station 3.4-2557 All All All
Application Synology Download Station 3.4-2558 All All All
Application Synology Download Station 3.5-2638 All All All
Application Synology Download Station 3.5-2705 All All All
Application Synology Download Station 3.5-2706 All All All
Application Synology Download Station 3.5-2955 All All All
Application Synology Download Station 3.5-2956 All All All
Application Synology Download Station 3.5-2962 All All All
Application Synology Download Station 3.5-2963 All All All
Application Synology Download Station 3.5-2967 All All All
Application Synology Download Station 3.5-2968 All All All
Application Synology Download Station 3.5-2970 All All All
Application Synology Download Station 3.5-2973 All All All
Application Synology Download Station 3.5-2980 All All All
Application Synology Download Station 3.5-2982 All All All
Application Synology Download Station 3.8.0-3416 All All All
Application Synology Download Station 3.8.1-3420 All All All
Application Synology Download Station 3.8.2-3455 All All All
Application Synology Download Station 3.8.3-3458 All All All
Application Synology Download Station 3.8.4-3468 All All All
Application Synology Download Station 3.2-2295 All All All
Application Synology Download Station 3.3-2382 All All All
Application Synology Download Station 3.3-2383 All All All
Application Synology Download Station 3.3-2386 All All All
Application Synology Download Station 3.4-2477 All All All
Application Synology Download Station 3.4-2478 All All All
Application Synology Download Station 3.4-2480 All All All
Application Synology Download Station 3.4-2485 All All All
Application Synology Download Station 3.4-2486 All All All
Application Synology Download Station 3.4-2489 All All All
Application Synology Download Station 3.4-2490 All All All
Application Synology Download Station 3.4-2514 All All All
Application Synology Download Station 3.4-2555 All All All
Application Synology Download Station 3.4-2557 All All All
Application Synology Download Station 3.4-2558 All All All
Application Synology Download Station 3.5-2638 All All All
Application Synology Download Station 3.5-2705 All All All
Application Synology Download Station 3.5-2706 All All All
Application Synology Download Station 3.5-2955 All All All
Application Synology Download Station 3.5-2956 All All All
Application Synology Download Station 3.5-2962 All All All
Application Synology Download Station 3.5-2963 All All All
Application Synology Download Station 3.5-2967 All All All
Application Synology Download Station 3.5-2968 All All All
Application Synology Download Station 3.5-2970 All All All
Application Synology Download Station 3.5-2973 All All All
Application Synology Download Station 3.5-2980 All All All
Application Synology Download Station 3.5-2982 All All All
Application Synology Download Station 3.8.0-3416 All All All
Application Synology Download Station 3.8.1-3420 All All All
Application Synology Download Station 3.8.2-3455 All All All
Application Synology Download Station 3.8.3-3458 All All All
Application Synology Download Station 3.8.4-3468 All All All

References

ReferenceSourceLinkTags
Synology-SA-17:28 Download Station | Synology Inc. CONFIRM www.synology.com Vendor Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report