CVE-2024-29229: High severity synology surveillance station vulnerability
Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29229?
CVE-2024-29229 is classified as a missing authorization vulnerability, which can lead to unauthorized access to sensitive information.
How do I fix CVE-2024-29229?
To mitigate CVE-2024-29229, upgrade Synology Surveillance Station to version 9.2.0-9289 or later.
What versions are affected by CVE-2024-29229?
CVE-2024-29229 affects Synology Surveillance Station versions prior to 9.2.0-9289 and 9.2.0-11289.
Who can exploit CVE-2024-29229?
CVE-2024-29229 can be exploited by remote authenticated users to access sensitive information.
What is the component vulnerable in CVE-2024-29229?
The vulnerable component in CVE-2024-29229 is the GetLiveViewPath webapi in Synology Surveillance Station.