CVE-2023-52949

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 2, 2024
CWE ID 306

Summary

CVE-2023-52949 is a vulnerability affecting Synology Active Backup for Business Agent before version 2.7.0-3221. This issue involves a missing authentication mechanism in the proxy settings functionality, which enables local users to exploit unspecified vectors and gain unauthorized access to user credentials. The consequences of this vulnerability could lead to significant security risks, including unauthorized access to sensitive data. Synology recommends users to update their software to the latest version to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Synology Active Backup for Business Agent

Affected Vendors

  • Synology