CVE-2024-11131
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security@synology.com (Secondary)
Description
A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.
Affected (3)
Products: Synology: Bc500 Firmware, Cc400w Firmware, Tc500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0-0525 |
| Running on/with | Platform Versions |
|---|---|
Synology Bc500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0-0525 |
| Running on/with | Platform Versions |
|---|---|
Synology Cc400w | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0-0525 |
| Running on/with | Platform Versions |
|---|---|
Synology Tc500 | All versions |
References (1)
Source: security@synology.com
Vendor Advisory
Timeline
No history available yet.