CVE ID | CVE-2024-39350 |
CVSS SCORE | 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
AFFECTED VENDORS |
Synology |
AFFECTED PRODUCTS |
BC500 |
VULNERABILITY DETAILS |
This vulnerability allows local attackers to escalate privileges on affected installations of Synology BC500 cameras. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of user accounts. The issue results from the lack of proper configuration for non-admin accounts. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. |
ADDITIONAL DETAILS |
Synology has issued an update to correct this vulnerability. More details can be found at:
https://www.synology.com/en-id/security/advisory/Synology_SA_23_15 |
DISCLOSURE TIMELINE |
|
CREDIT | Romain JOUET (@JouetR), Baptiste MOINE (@Creased_) from Synacktiv (@Synacktiv) |