Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29241


Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors.


Published

2024-03-28T07:16:12.177

Last Modified

2025-08-12T17:34:11.550

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology surveillance_station < 9.2.0-9289 Yes
Operating System synology diskstation_manager 6.2 No
Application synology surveillance_station < 9.2.0-11289 Yes
Operating System synology diskstation_manager 7.1 No
Operating System synology diskstation_manager 7.2 No

References