Seems like there is a more localized page available for your location.
Serie Bee de Synology
Productos A-Z

Synology-SA-24:24 Synology Camera (PWN2OWN 2024)

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Critical
Status
Resolved

Abstract

Multipe vulnerabilities allow remote attackers to execute arbitrary code or execute arbitrary commands on a susceptible version of Synology Camera BC500 Firmware, Synology Camera CC400W Firmware and Synology Camera TC500 Firmware.

The vulnerability reported by PWN2OWN 2024 (ZDI-CAN-25538) has been addressed.

Affected Products

Product Severity Fixed Release Availability
BC500 Critical Upgrade to 1.2.0-0525 or above.
CC400W Critical Upgrade to 1.2.0-0525 or above.
TC500 Critical Upgrade to 1.2.0-0525 or above.

Mitigation

None

Detail

  • CVE-2024-11131
    • Severity: Critical
    • CVSS3 Base Score: 9.8
    • CVSS3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.

Acknowledgement

  • HANRYEOL PARK, HYOJIN LEE, HYEOKJONG YUN, HYEONJUN LEE, DOWON KWAK, ZIEN (https://zi-en.io/)

  • Viettel Cyber Security (@vcslab)

Reference

CVE-2024-11131

Revision

Revision Date Description
1 2024-11-14 Initial public release.
2 2025-03-19 Disclosed vulnerability details.