Synology DSM Product Security Update Advisory (CVE-2024-29241)

Overview

 

Synology has released a security update to fix vulnerabilities in its products. users of affected products are advised to update to the latest version.

 

Affected Products

 

Synology Surveillance Station prior to 9.2.0-9289, 9.2.0-11289

 

Resolved Vulnerabilities

 

Security constraint bypass vulnerability due to a missing authentication vulnerability in the system webapi component of Synology Surveillance Station (CVE-2024-29241)

 

Vulnerability Patches

 

vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

  • Version 9.2.0-9289 or above for DSM 6.2
  • Version 9.2.0-11289 or above for DSM 7.1, 7.2

 

Referenced Sites

 

[1] Synology-SA-24:04 Surveillance Station

https://www.synology.com/en-global/security/advisory/Synology_SA_24_04