← العودة للجدول
CVE-2024-29241
CVE-2024-29241 — Synology: Missing authorization vulnerability in System webapi component in Synology Surve
📅 2024-03-28
🔴 Critical 🔥 No NVD Exploit Synology CVSS 9.9

📋 الوصف الكامل

Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors.

💻 الأنظمة المتأثرة

Synology

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2024-29241

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2024-29241 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←