PT-2024-9409 · Synology · Synology Surveillance Station

Zhao Runzi

·

Published

2024-03-28

·

Updated

2024-12-04

·

CVE-2023-52944

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Synology Surveillance Station versions prior to 9.2.0-11289 and 9.2.0-9289
Description: The issue is related to an incorrect authorization vulnerability in the ActionRule webapi component. This vulnerability allows remote authenticated users to perform limited actions on the set action rules function. The exploitation of this vulnerability can enable a remote attacker to elevate their privileges.
Recommendations: For Synology Surveillance Station versions prior to 9.2.0-11289, update to version 9.2.0-11289 or later. For Synology Surveillance Station versions prior to 9.2.0-9289, update to version 9.2.0-9289 or later. As a temporary workaround, consider restricting access to the ActionRule webapi component until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-11102
CVE-2023-52944

Affected Products

Synology Surveillance Station