Improper Control of Dynamically-Managed Code Resources in Synology DiskStation Manager
CVE-2024-5401

4.3MEDIUM

What is CVE-2024-5401?

A security vulnerability exists in the WebAPI component of Synology DiskStation Manager, allowing remote authenticated users to gain elevated privileges without proper authorization. This issue affects multiple versions prior to the specified updates, enabling unauthorized access through unspecified methods. Users are advised to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

DiskStation Manager (DSM) 7.2.2

DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806

DiskStation Manager (DSM) 7.2.1 < 7.2.1-69057-2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vo Van Thong of GE Security (VNG) (https://www.linkedin.com/in/thongvv3/)
.
CVE-2024-5401 : Improper Control of Dynamically-Managed Code Resources in Synology DiskStation Manager