CVE-2023-52949: Medium severity synology active backup for business agent vulnerability
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52949?
CVE-2023-52949 has a high severity rating due to the potential for local users to access sensitive user credentials.
How do I fix CVE-2023-52949?
To mitigate CVE-2023-52949, upgrade Synology Active Backup for Business Agent to version 2.7.0-3221 or later.
What type of vulnerability is CVE-2023-52949?
CVE-2023-52949 is categorized as a missing authentication vulnerability affecting proxy settings functionality.
Who is affected by CVE-2023-52949?
Local users of Synology Active Backup for Business Agent versions prior to 2.7.0-3221 are affected by CVE-2023-52949.
What can attackers achieve by exploiting CVE-2023-52949?
Attackers can potentially obtain user credentials by exploiting the missing authentication in CVE-2023-52949.