CVE-2022-3576: Synology Diskstation Manager

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

Affected products

  • Synology Diskstation Manager: before 7.1.1-42962-2 (fixed in 7.1.1-42962-2)

Published 2022-10-20. Last modified 2026-06-17.