CVE-2024-10445: Medium severity synology beestation bst150-4t vulnerability
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10445?
CVE-2024-10445 has been rated as a high severity vulnerability due to improper certificate validation leading to potential security risks.
How do I fix CVE-2024-10445?
To mitigate CVE-2024-10445, update Synology BeeStation Manager, DiskStation Manager, or Unified Controller to the latest version as specified in the official advisory.
Which versions are affected by CVE-2024-10445?
CVE-2024-10445 affects Synology BeeStation Manager before 1.1-65374, DiskStation Manager before 6.2.4-25556-8 and several 7.x versions, and Unified Controller before 3.1.4-2.
What systems are impacted by CVE-2024-10445?
CVE-2024-10445 impacts Synology BeeStation Manager, DiskStation Manager, and Unified Controller, all manufactured by Synology.
What is the nature of the vulnerability in CVE-2024-10445?
CVE-2024-10445 is an improper certificate validation vulnerability that can be exploited within the update functionality of affected Synology products.