Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5746


A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected: BC500 and TC500.


Published

2023-10-25T18:17:44.770

Last Modified

2024-11-21T08:42:24.153

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-134

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System synology bc500_firmware < 1.0.5-0185 Yes
Hardware synology bc500 - No
Operating System synology tc500_firmware < 1.0.5-0185 Yes
Hardware synology tc500 - No

References