Critical Vulnerability on Synology Products CVE-2024-10441
BACKGROUND
CVSS Score: Base 9.8 Critical
Synology has disclosed a critical security vulnerability affecting several of its products, including Synology BeeStation Manager (BSM), Synology DiskStation Manager (DSM), and Synology Unified Controller (DSMUC).
It involves improper encoding or escaping of output vulnerabilities in the system plugin daemon within the affected products, allowing remote attackers to execute arbitrary code without user interaction.
IMPACT
- Allows remote attackers to execute arbitrary code via unspecified vectors.
- Enables unauthorized file access and modification.
- Poses a significant risk of system compromise and data breaches.
| Products | Fixed Versions | |
| 1 | BeeStation OS 1.1 | Upgrade to 1.1-65374 or above |
| 2 | BeeStation OS 1.0 | Upgrade to 1.1-65374 or above |
| 3 | DSM 6.2.4 | Upgrade to 6.2.4-25556-8 or above |
| 4 | DSM 7.1.1 | Upgrade to 7.1.1-42962-7 or above |
| 5 | DSM 7.2 | Upgrade to 7.2-64570-4 or above |
| 6 | DSM 7.2.1 | Upgrade to 7.2.1-69057-6 or above |
| 7 | DSM 7.2.2 | Upgrade to 7.2.2-72806-1 or above |
| 8 | DSMUC 3.1.4 | Upgrade to 3.1.4-23079 or above |
RECOMMENDATIONS
- Immediately update to the latest versions of BSM, DSM, and DSMUC.
- Implement network segmentation to limit remote access to vulnerable systems.
- Configure firewalls to restrict unnecessary network exposure.
- Regularly monitor systems and networks for signs of unauthorized access or unusual activity.
- Conduct regular vulnerability scans on Synology devices to identify and address potential security weaknesses.
REFERENCES
https://www.synology.com/en-global/security/advisory/Synology_SA_24_23