CVE-2024-47266

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Feb 13, 2025
CWE ID 22

Summary

CVE-2024-47266 is a path traversal vulnerability affecting Synology Active Backup for Business versions before 2.7.1-13234, 2.7.1-23234, and 2.7.1-3234. Authenticated users with administrator privileges can exploit this issue to read specific non-sensitive files through improper limitation of file pathnames to restricted directories. The exact attack vectors are unspecified, but this vulnerability poses a risk to the confidentiality of data stored in the affected Synology backup solution. Users are advised to update to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share