HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-39351

CVSS 7.2v3.1pub. 2024-06-28upd. 2025-04-10

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Synology Bc500

    HW
    Synology
    all versions
  • Synology Bc500 Firmware

    OS
    Synology
    < 1.0.7-0298
  • Synology Tc500

    HW
    Synology
    all versions
  • Synology Tc500 Firmware

    OS
    Synology
    < 1.0.7-0298
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-11131CRITICAL9.8PL ✓same product

Out-of-bounds read w firmware kamer Synology umożliwia RCE

CVE-2024-39349CRITICAL9.8PL ✓same product

Buffer Overflow w firmware kamer Synology BC500/TC500 umożliwia RCE

CVE-2023-5746CRITICAL9.8PL ✓same product

RCE przez format string w firmware kamer Synology BC500 i TC500

CVE-2023-47802HIGH7.2same product

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injec...

CVE-2024-39350HIGH7.5same product

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows ma...