First published: Thu Sep 26 2024(Updated: )
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Active Backup for Business Agent | <2.6.0-3101 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52947 is categorized as a critical vulnerability due to its potential impact on the logout functionality.
To fix CVE-2023-52947, update Synology Active Backup for Business Agent to version 2.6.3-3101 or later.
CVE-2023-52947 affects users of Synology Active Backup for Business Agent versions prior to 2.6.3-3101.
The impact of CVE-2023-52947 allows local users to log out of the client without impacting the backup functionality.
Currently, there is no specific workaround for CVE-2023-52947; updating the software is recommended.