Lucene search

K
cveSynologyCVE-2024-39350
HistoryJun 28, 2024 - 7:15 a.m.

CVE-2024-39350

2024-06-2807:15:06
CWE-290
synology
web.nvd.nist.gov
24
rtsp
authentication bypass
spoofing
man-in-the-middle attack
unspecified vectors
synology camera firmware
bc500
tc500

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

29.3%

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

CNA Affected

[
  {
    "vendor": "Synology",
    "product": "Camera Firmware",
    "versions": [
      {
        "version": "1.0",
        "status": "affected",
        "lessThan": "1.0.7-0298",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "affected",
    "platforms": [
      "BC500",
      "TC500"
    ]
  }
]

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

29.3%

Related for CVE-2024-39350