CVE-2024-39352 MEDIUM

CVE-2024-39352

Vendor Synology
Product Camera Firmware
Weakness CWE-863 · Incorrect authorization
Published June 28, 2024
Last update August 2, 2024

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

Key dates

02Disclosure timeline

June 28, 2024 CVE published
August 2, 2024 Record updated