PT-2024-9410 · Synology · Synology Surveillance Station

Zhao Runzi

·

Published

2024-03-28

·

Updated

2024-12-04

·

CVE-2023-52943

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Synology Surveillance Station versions prior to 9.2.0-11289 and 9.2.0-9289
Description: The issue is related to an incorrect authorization vulnerability in the Alert.Setting webapi component. This allows remote authenticated users to perform limited actions on the alerting function via unspecified vectors. The vulnerability is associated with deficiencies in the authorization mechanism, which can be exploited by a remote attacker to elevate their privileges.
Recommendations: For Synology Surveillance Station versions prior to 9.2.0-11289, update to version 9.2.0-11289 or later. For Synology Surveillance Station versions prior to 9.2.0-9289, update to version 9.2.0-9289 or later. As a temporary workaround, consider restricting access to the Alert.Setting webapi component until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-11103
CVE-2023-52943

Affected Products

Synology Surveillance Station