CVE-2024-10445
Synology BeeStation BST150-4T Unnecessary Privileges Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper certificate validation vulnerability in the update functionality in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to write limited files via unspecified vectors.
La vulnerabilidad de validación de certificado incorrecta en la funcionalidad de actualización en Synology BeeStation Manager (BSM) anterior a 1.1-65374, Synology DiskStation Manager (DSM) anterior a 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 y 7.2.2-72806-1 y Synology Unified Controller (DSMUC) anterior a 3.1.4-23079 permite a atacantes remotos escribir archivos limitados a través de vectores no especificados.
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of file commands. The specific flaw exists within the handling of files as the root user. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-10-28 CVE Reserved
- 2025-03-19 CVE Published
- 2025-05-01 CVE Updated
- 2025-08-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.synology.com/en-global/security/advisory/Synology_SA_24_20 | 2025-03-19 | |
https://www.synology.com/en-global/security/advisory/Synology_SA_24_23 | 2025-03-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Synology Search vendor "Synology" | DiskStation Manager (DSM) Search vendor "Synology" for product "DiskStation Manager (DSM)" | >= 7.2.2 < 7.2.2-72806-1 Search vendor "Synology" for product "DiskStation Manager (DSM)" and version " >= 7.2.2 < 7.2.2-72806-1" | en |
Affected
| ||||||
Synology Search vendor "Synology" | DiskStation Manager (DSM) Search vendor "Synology" for product "DiskStation Manager (DSM)" | >= 7.2.1 < 7.2.1-69057-6 Search vendor "Synology" for product "DiskStation Manager (DSM)" and version " >= 7.2.1 < 7.2.1-69057-6" | en |
Affected
| ||||||
Synology Search vendor "Synology" | DiskStation Manager (DSM) Search vendor "Synology" for product "DiskStation Manager (DSM)" | >= 7.2 < 7.2-64570-4 Search vendor "Synology" for product "DiskStation Manager (DSM)" and version " >= 7.2 < 7.2-64570-4" | en |
Affected
| ||||||
Synology Search vendor "Synology" | DiskStation Manager (DSM) Search vendor "Synology" for product "DiskStation Manager (DSM)" | >= 7.1.0 < 7.1.1-42962-7 Search vendor "Synology" for product "DiskStation Manager (DSM)" and version " >= 7.1.0 < 7.1.1-42962-7" | en |
Affected
| ||||||
Synology Search vendor "Synology" | DiskStation Manager (DSM) Search vendor "Synology" for product "DiskStation Manager (DSM)" | >= 6.2.0 < 6.2.4-25556-8 Search vendor "Synology" for product "DiskStation Manager (DSM)" and version " >= 6.2.0 < 6.2.4-25556-8" | en |
Affected
| ||||||
Synology Search vendor "Synology" | BeeStation OS (BSM) Search vendor "Synology" for product "BeeStation OS (BSM)" | >= 1.1 < 1.1-65374 Search vendor "Synology" for product "BeeStation OS (BSM)" and version " >= 1.1 < 1.1-65374" | en |
Affected
| ||||||
Synology Search vendor "Synology" | BeeStation OS (BSM) Search vendor "Synology" for product "BeeStation OS (BSM)" | >= 1.0 < 1.1-65374 Search vendor "Synology" for product "BeeStation OS (BSM)" and version " >= 1.0 < 1.1-65374" | en |
Affected
|