CVE-2024-47264
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2024-47264 is a Path Traversal vulnerability affecting Synology Active Backup for Business versions before 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. This issue permits remote authenticated users with administrator privileges to delete arbitrary files through unspecified vectors within the agent-related functionality. This vulnerability occurs due to an improper limitation of a pathname to a restricted directory. Successful exploitation could result in significant data loss or system compromise. It is strongly recommended that affected users upgrade to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.