Buffer Copy Vulnerability Affects Synology Login Service
CVE-2024-5463

6.5MEDIUM

Key Information:

Vendor

Synology

Vendor
CVE Published:
4 June 2024

What is CVE-2024-5463?

A buffer copy vulnerability exists in the login component of Synology Camera Firmware, which does not properly validate the size of input data. This oversight can allow remote attackers to exploit the vulnerability by manipulating input, leading to denial-of-service attacks. The affected models, BC500 and TC500, may experience service interruptions due to an automatic restart of the login service. It is crucial for users to update their firmware to mitigate potential risks.

Affected Version(s)

Camera Firmware 1.1

Camera Firmware 1.1 < 1.1.1-0383

Camera Firmware 1.0 < 1.1.1-0383

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Maugeri (https://www.linkedin.com/in/andreamaugeri)
.