CVE-2024-39352

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Jun 28, 2024
CWE ID 863

Summary

CVE-2024-39352 is a newly discovered vulnerability affecting Synology Camera firmware. It involves an incorrect authorization issue in the firmware upgrade functionality. This flaw enables remote authenticated users with administrator privileges to bypass the firmware integrity check process through unspecified vectors. Synology BC500 and TC500 models running firmware versions below 1.0.7-0298 are vulnerable to this exploit. Unauthorized upgrades could lead to significant security risks or potential data loss. Users are advised to upgrade their firmware as soon as patches are released to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share