{"id":2700,"date":"2025-03-19T10:03:38","date_gmt":"2025-03-19T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/19\/critical-synology-vulnerability-let-attackers-remote-execute-arbitrary-code\/"},"modified":"2025-03-19T10:03:38","modified_gmt":"2025-03-19T10:03:38","slug":"critical-synology-vulnerability-let-attackers-remote-execute-arbitrary-code","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/19\/critical-synology-vulnerability-let-attackers-remote-execute-arbitrary-code\/","title":{"rendered":"Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code"},"content":{"rendered":"<p>    Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A severe vulnerability in Synology\u2019s DiskStation Manager (DSM) allows remote attackers to execute arbitrary code with no user interaction.\u00a0<\/p>\n<p>The flaw, disclosed during PWN2OWN 2024, received a Critical severity rating with a <a href=\"https:\/\/cybersecuritynews.com\/cvss-v4-0-vulnerability-scoring\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVSS score<\/a> of 9.8, indicating its potential for widespread exploitation.<\/p>\n<p>The primary vulnerability, identified as CVE-2024-10441, stems from improper encoding or escaping of output in the system plugin daemon.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Critical Synology Vulnerability<\/strong><\/h2>\n<p>This critical flaw affects multiple Synology products, including DSM versions prior to specified patched releases, BeeStation Manager (BSM), and Synology Unified Controller (DSMUC).<\/p>\n<p>This vulnerability represents one of the most serious security issues discovered in Synology products this year. With a CVSS score of 9.8 and requiring no <a href=\"https:\/\/cybersecuritynews.com\/4-things-to-know-about-user-authentication-for-a-saas-app\/\" target=\"_blank\" rel=\"noreferrer noopener\">user authentication<\/a>, attackers could potentially take complete control of vulnerable systems.<\/p>\n<p>The technical vector is characterized as CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H, indicating network accessibility, low attack complexity, no privileges required, no user interaction needed, and potential for high confidentiality, integrity, and availability impact.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>-Synology BeeStation Manager (BSM) before 1.1-65374- Synology DiskStation Manager (DSM) before 6.2.4-25556-8- DSM before 7.1.1-42962-7- DSM before 7.2-64570-4- DSM before 7.2.1-69057-6- DSM before 7.2.2-72806-1- Synology Unified Controller (DSMUC) before 3.1.4-23079<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Execute arbitrary code\u00a0<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>Network access to target<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>9.8 Critical<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Medium-Severity Issues<\/strong><\/h2>\n<p>CVE-2024-50629: A vulnerability in the web API component with a CVSS score of 5.3 that allows attackers to read limited files via unspecified vectors.<\/p>\n<p>CVE-2024-10445: An improper certificate validation vulnerability in the update functionality with a CVSS score of 4.3 that enables adjacent attackers to write limited files.<\/p>\n<p>The vulnerabilities were discovered by prominent security researchers including Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from DEVCORE Research Team, along with Ryan Emmons (@the_emmons) and Team Smoking Barrels.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Affected Products and Remediation<\/strong><\/h2>\n<p>Synology has released patches for all affected products. Users are strongly advised to update to the following versions:<\/p>\n<ul class=\"wp-block-list\">\n<li>DSM 7.2.2: Upgrade to 7.2.2-72806-1 or above<\/li>\n<li>DSM 7.2.1: Upgrade to 7.2.1-69057-6 or above<\/li>\n<li>DSM 7.2: Upgrade to 7.2-64570-4 or above<\/li>\n<li>DSM 7.1: Upgrade to 7.1.1-42962-7 or above<\/li>\n<li>DSM 6.2: Upgrade to 6.2.4-25556-8 or above<\/li>\n<li>DSMUC 3.1: Upgrade to 3.1.4-23079 or above<\/li>\n<\/ul>\n<p>Notably, no mitigations are available other than applying the updates, underscoring the importance of immediate patching.<\/p>\n<p>\u201cThe fact that such critical flaws existed in widely deployed storage systems should remind organizations to keep security at the forefront of their product development.\u201d<\/p>\n<p>Given the severity and remote exploitability of CVE-2024-10441, organizations, and individuals using Synology NAS devices should treat this update as an emergency patch.\u00a0<\/p>\n<p>Exposed, unpatched systems could be compromised through automated scanning and exploitation attempts.<\/p>\n<p>Synology initially <a href=\"https:\/\/www.synology.com\/en-global\/security\/advisory\/Synology_SA_24_20\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> this security advisory on November 5, 2024, with subsequent updates releasing patches for various product lines. <\/p>\n<p>The most recent update on March 19, 2025, disclosed complete vulnerability details after providing users adequate time to update their systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enrichment&amp;utm_content=plans&amp;utm_term=180325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/synologys-diskstation-manager-vulnerability\/\">Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/synologys-diskstation-manager-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code A severe vulnerability in Synology\u2019s DiskStation Manager (DSM) allows remote attackers to execute arbitrary code with no user interaction.\u00a0 The flaw, disclosed during PWN2OWN 2024, received a Critical severity rating with a CVSS score of 9.8, indicating its potential for widespread exploitation. The primary vulnerability, identified [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-2700","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2700"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2700"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2700\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}