PT-2024-14787 · Synology · Synology Active Backup For Business Agent

Zhao Runzi

·

Published

2024-09-25

·

Updated

2024-10-02

·

CVE-2023-52949

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Active Backup for Business Agent versions prior to 2.7.0-3221
Description The issue involves missing authentication for a critical function in the proxy settings functionality, allowing local users to obtain user credentials via unspecified vectors.
Recommendations For Synology Active Backup for Business Agent versions prior to 2.7.0-3221, update to version 2.7.0-3221 or later to resolve the issue.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-52949

Affected Products

Synology Active Backup For Business Agent