CVE-2024-47265

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 13, 2025
CWE ID 22

Summary

CVE-2024-47265 is a path traversal vulnerability affecting Synology Active Backup for Business versions 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. This issue enables remote authenticated users to write specific files outside of restricted directories, as a result of improper limitation checks in the encrypted share umount functionality. The precise vectors leading to exploitation are currently undefined. Successful exploitation could potentially lead to significant data loss or unauthorized file modification. Users are advised to upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share