CVE-2024-10442
CVSS 3.1 Score 10 of 10 (high)
Details
Published Mar 19, 2025
CWE ID 193
Summary
CVE-2024-10442 is a critical vulnerability affecting Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423, and Synology Unified Controller (DSMUC) before 3.1.4-23079. An off-by-one error in the transmission component of these software versions allows remote attackers to execute arbitrary code. This vulnerability could lead to a broader impact across the system, potentially exploited via unspecified vectors, making it essential for users to update their software promptly to the patched versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.