Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29240


Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors.


Published

2024-03-28T07:16:11.083

Last Modified

2025-01-14T21:24:20.010

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology surveillance_station < 9.2.0-9289 Yes
Operating System synology diskstation_manager 6.2 No
Application synology surveillance_station < 9.2.0-11289 Yes
Operating System synology diskstation_manager 7.1 No
Operating System synology diskstation_manager 7.2 No

References