PT-2024-9746 · Synology · Synology Media Server

Team Tgls

·

Published

2024-05-03

·

Updated

2026-01-29

·

CVE-2024-4464

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Media Server versions prior to 1.4-2680 Synology Media Server versions prior to 2.0.5-3152 Synology Media Server versions prior to 2.2.0-3325
Description The issue is related to an authorization bypass vulnerability through a user-controlled key in the streaming service of Synology Media Server. This vulnerability allows remote attackers to read specific files via unspecified vectors.
Recommendations For Synology Media Server versions prior to 1.4-2680, update to version 1.4-2680 or later. For Synology Media Server versions prior to 2.0.5-3152, update to version 2.0.5-3152 or later. For Synology Media Server versions prior to 2.2.0-3325, update to version 2.2.0-3325 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2024-11482
CVE-2024-4464

Affected Products

Synology Media Server