Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.
2024-12-04T07:15:05.790
2025-03-06T14:30:43.413
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | surveillance_station | < 9.2.0-9289 | Yes |
| Operating System | synology | diskstation_manager | 6.2 | No |
| Application | synology | surveillance_station | < 9.2.0-11289 | Yes |
| Operating System | synology | diskstation_manager | 7.1 | No |
| Operating System | synology | diskstation_manager | 7.2 | No |