CVE-2016-10323: Synology Photo Station

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.

Affected products

  • Synology Photo Station: before 6.3-2958 (fixed in 6.3-2958)

Published 2017-04-10. Last modified 2026-06-17.