Path Traversal Vulnerability in Synology Active Backup for Business
CVE-2024-47264
4.9MEDIUM
Summary
A path traversal vulnerability in Synology Active Backup for Business allows remote authenticated users with admin privileges to navigate and manipulate the file directory structure. This issue could lead to the unauthorized deletion of arbitrary files, posing significant risks to data integrity and operational functionalities. It is crucial for organizations using affected versions to implement the latest security patches and monitor for any suspicious activities related to unauthorized file access.
Affected Version(s)
Active Backup for Business *
Active Backup for Business * < 2.7.1-3234
Active Backup for Business * < 2.7.1-13234
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhao Runzi (赵润梓)