Skip to main content

Critical Vulnerability on Synology Products CVE-2024-10441

BACKGROUND
 

CVSS Score: Base 9.8 Critical
Synology has disclosed a critical security vulnerability affecting several of its products, including Synology BeeStation Manager (BSM), Synology DiskStation Manager (DSM), and Synology Unified Controller (DSMUC).
It involves improper encoding or escaping of output vulnerabilities in the system plugin daemon within the affected products, allowing remote attackers to execute arbitrary code without user interaction.

IMPACT

  • Allows remote attackers to execute arbitrary code via unspecified vectors.
  • Enables unauthorized file access and modification.
  • Poses a significant risk of system compromise and data breaches.
 ProductsFixed Versions
1BeeStation OS 1.1Upgrade to 1.1-65374 or above
2BeeStation OS 1.0Upgrade to 1.1-65374 or above
3DSM 6.2.4Upgrade to 6.2.4-25556-8 or above
4DSM 7.1.1Upgrade to 7.1.1-42962-7 or above
5DSM 7.2Upgrade to 7.2-64570-4 or above
6DSM 7.2.1Upgrade to 7.2.1-69057-6 or above
7DSM 7.2.2Upgrade to 7.2.2-72806-1 or above
8DSMUC 3.1.4Upgrade to 3.1.4-23079 or above

RECOMMENDATIONS

  • Immediately update to the latest versions of BSM, DSM, and DSMUC.
  • Implement network segmentation to limit remote access to vulnerable systems.
  • Configure firewalls to restrict unnecessary network exposure.
  • Regularly monitor systems and networks for signs of unauthorized access or unusual activity.
  • Conduct regular vulnerability scans on Synology devices to identify and address potential security weaknesses.

 

REFERENCES

https://www.synology.com/en-global/security/advisory/Synology_SA_24_23

https://securityonline.info/cve-2024-10441-cvss-9-8-synology-patches-critical-code-execution-flaw-in-multiple-products/

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.