CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-45538

CVSS 9.6v3.1pub. 2025-12-04upd. 2025-12-05

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

🤖 AI Analysis
How it works

The attacker exploits the CSRF mechanism by forcing a logged-in user to unknowingly execute a crafted request to the WebAPI Framework interface of the Synology device. The request is executed in the context of the victim's session, allowing bypass of standard authorization. As a result, the application processes the malicious request as legitimate, leading to arbitrary code execution on the device (RCE). The attack does not require privileges on the attacker's side, but requires interaction from an authenticated user (e.g., clicking a crafted link).

Impact

An attacker can execute arbitrary code on the vulnerable device, leading to complete system takeover, including violation of data confidentiality and integrity, and loss of NAS service availability.

Mitigation & patch

Synology DiskStation Manager should be updated to version 7.2.1-69057-2 or later in the 7.2.1 branch, to version 7.2.2-72806 or later in the 7.2.2 branch, and Synology Unified Controller (DSMUC) to version 3.1.4-23079 or later. Details available in the official Synology SA-24-27 security bulletin.

Who is affected

Synology DiskStation Manager (DSM) in versions prior to 7.2.1-69057-2 and 7.2.2-72806; Synology Unified Controller (DSMUC) in versions prior to 3.1.4-23079.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Synology Diskstation Manager

    OS
    Synology
    7.2.1-69057 – 7.2.1-69057-2 (excl.)7.2.2-72803 – 7.2.2-72806 (excl.)
  • Synology Diskstation Manager Unified Controller

    OS
    Synology
    3.1-23028 – 3.1.4-23079 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-10441CRITICAL9.8PL ✓same product

RCE w Synology BeeStation OS i DSM — błąd kodowania wyjścia w systemowym daemonie

CVE-2024-10442CRITICAL10.0PL ✓same product

RCE przez błąd off-by-one w komponencie transmisji Synology Replication Service

CVE-2024-10443CRITICAL9.8PL ✓same product

OS Command Injection w Synology BeePhotos i Synology Photos — RCE bez uwierzytelnienia

CVE-2024-29241CRITICAL9.9PL ✓same product

Brak autoryzacji w Synology Surveillance Station — zapis konfiguracji i restart NAS

CVE-2022-27625CRITICAL10.0PL ✓same product

RCE w Out-of-Band Management Synology DSM — przepełnienie bufora