CVE-2015-2851: Synology Cloud Station

Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.

client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.

Affected products

  • Synology Cloud Station: version 1.1-2291 only; version 2.0-2291 only; version 2.0-2402 only; version 2.1-2561 only; version 2.1-2570 only; version 2.1-2577 only; …

Published 2015-05-30. Last modified 2026-06-17.