CVE-2024-29236
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-29236 is a newly disclosed SQL Injection vulnerability affecting Synology Surveillance Station's AudioPattern.Delete webapi component. This issue, present in versions prior to 9.2.0-9289 and 9.2.0-11289, allows remote, authenticated users to inject malicious SQL commands into the system via unspecified vectors. Exploitation of this vulnerability could result in unauthorized access to sensitive data or unintended modifications to the database, potentially compromising the entire system. System administrators are urged to update their Synology Surveillance Station installations to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Synology DiskStation
- Synology Surveillance Station
Affected Vendors
- Synology