Description
Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-26255 | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors. |
References
History
Tue, 12 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and write sensitive configurations in DSM via unspecified vectors. | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors. |
Fri, 01 Aug 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Aug 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors. | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and write sensitive configurations in DSM via unspecified vectors. |
Tue, 14 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology diskstation Manager Synology surveillance Station |
|
| CPEs | cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology
Synology diskstation Manager Synology surveillance Station |
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2025-08-12T08:09:15.488Z
Reserved: 2024-03-19T06:14:19.316Z
Link: CVE-2024-29241
Updated: 2024-08-02T01:10:54.736Z
Status : Analyzed
Published: 2024-03-28T07:16:12.177
Modified: 2025-08-12T17:34:11.550
Link: CVE-2024-29241
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD