PT-2024-9746 · Synology · Synology Media Server
Team Tgls
·
Published
2024-05-03
·
Updated
2026-01-29
·
CVE-2024-4464
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Synology Media Server versions prior to 1.4-2680
Synology Media Server versions prior to 2.0.5-3152
Synology Media Server versions prior to 2.2.0-3325
Description
The issue is related to an authorization bypass vulnerability through a user-controlled key in the streaming service of Synology Media Server. This vulnerability allows remote attackers to read specific files via unspecified vectors.
Recommendations
For Synology Media Server versions prior to 1.4-2680, update to version 1.4-2680 or later.
For Synology Media Server versions prior to 2.0.5-3152, update to version 2.0.5-3152 or later.
For Synology Media Server versions prior to 2.2.0-3325, update to version 2.2.0-3325 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Media Server