// For flags

CVE-2024-10442

 

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.

La vulnerabilidad de error de uno en uno en el componente de transmisión en Synology Replication Service anterior a 1.0.12-0066, 1.2.2-0353 y 1.3.0-0423 y Synology Unified Controller (DSMUC) anterior a 3.1.4-23079 permite a atacantes remotos ejecutar código arbitrario, lo que podría generar un impacto más amplio en todo el sistema a través de vectores no especificados.

*Credits: Jack Dates | RET2 Systems jack@ret2.io
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-10-28 CVE Reserved
  • 2025-03-19 CVE Published
  • 2025-03-19 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-193: Off-by-one Error
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Synology
Search vendor "Synology"
Unified Controller (DSMUC)
Search vendor "Synology" for product "Unified Controller (DSMUC)"
>= 3.1.0 < 3.1.4-23079
Search vendor "Synology" for product "Unified Controller (DSMUC)" and version " >= 3.1.0 < 3.1.4-23079"
en
Affected
Synology
Search vendor "Synology"
Replication Service
Search vendor "Synology" for product "Replication Service"
< 1.2.2-0353
Search vendor "Synology" for product "Replication Service" and version " < 1.2.2-0353"
en
Affected
Synology
Search vendor "Synology"
Replication Service
Search vendor "Synology" for product "Replication Service"
< 1.0.12-0066
Search vendor "Synology" for product "Replication Service" and version " < 1.0.12-0066"
en
Affected
Synology
Search vendor "Synology"
Replication Service
Search vendor "Synology" for product "Replication Service"
< 1.3.0-0423
Search vendor "Synology" for product "Replication Service" and version " < 1.3.0-0423"
en
Affected