CVE-2024-29231: Out-of-bounds Read
Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29231?
CVE-2024-29231 has a medium severity rating as it allows remote authenticated users to bypass security constraints.
How do I fix CVE-2024-29231?
To fix CVE-2024-29231, users should upgrade to Synology Surveillance Station version 9.2.0-9289 or newer.
Which versions of Synology Surveillance Station are affected by CVE-2024-29231?
CVE-2024-29231 affects Synology Surveillance Station versions prior to 9.2.0-9289 and 9.2.0-11289.
Can CVE-2024-29231 be exploited by unauthenticated users?
No, CVE-2024-29231 can only be exploited by remote authenticated users.
What is the impact of CVE-2024-29231 on users?
The impact of CVE-2024-29231 is that it allows authenticated users to bypass security constraints which could lead to unauthorized access.