CVE-2024-29240: Medium severity Synology Surveillance Station vulnerability
Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29240?
CVE-2024-29240 is classified as a medium severity vulnerability due to the potential for denial-of-service attacks.
How do I fix CVE-2024-29240?
To fix CVE-2024-29240, update Synology Surveillance Station to version 9.2.0-11289 or later.
Who is affected by CVE-2024-29240?
CVE-2024-29240 affects users of Synology Surveillance Station versions prior to 9.2.0-11289.
What type of vulnerability is CVE-2024-29240?
CVE-2024-29240 is a missing authorization vulnerability that allows remote authenticated users to perform denial-of-service attacks.
Can CVE-2024-29240 be exploited remotely?
Yes, CVE-2024-29240 can be exploited remotely by authenticated users, making it imperative to apply the necessary updates.