Improper Certificate Validation in Synology DiskStation Manager Products
CVE-2024-10444
7.5HIGH
What is CVE-2024-10444?
A vulnerability in the LDAP utilities of Synology DiskStation Manager (DSM) before specific versions permits man-in-the-middle attackers to potentially hijack administrator authentication. This weakness arises from improper validation of certificates, leaving the system open to unauthorized access through unidentified methods. Users are urged to update their DSM versions to protect against this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DiskStation Manager (DSM) 7.2.2
DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806-3
DiskStation Manager (DSM) 7.2.1 < 7.2.1-69057-7
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published