CVE-2024-10444: High severity synology photos diskstation manager vulnerability
Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10444?
CVE-2024-10444 has been classified as a high-severity vulnerability due to its potential for exploitation in man-in-the-middle attacks.
How do I fix CVE-2024-10444?
To mitigate CVE-2024-10444, upgrade your Synology DiskStation Manager to version 7.1.1-42962-8 or higher.
Which versions of Synology DiskStation Manager are affected by CVE-2024-10444?
CVE-2024-10444 affects Synology DiskStation Manager versions prior to 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3.
What type of attack can exploit CVE-2024-10444?
CVE-2024-10444 can be exploited through man-in-the-middle attacks that hijack administrator authentication.
Is there a workaround for CVE-2024-10444 while waiting for a patch?
It is recommended to implement secure network practices, including using VPNs, as an interim measure until the software is updated.