CVE-2024-39347: Medium severity synology router manager vulnerability
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39347?
CVE-2024-39347 is considered a high-severity vulnerability due to its potential for allowing unauthorized access to sensitive intranet resources.
How do I fix CVE-2024-39347?
To fix CVE-2024-39347, update Synology Router Manager to version 1.2.5-8227-12 or later, or 1.3.1-9346-9 or later.
What are the potential impacts of CVE-2024-39347?
The impact of CVE-2024-39347 includes unauthorized access to sensitive intranet resources by man-in-the-middle attackers.
Which versions of Synology Router Manager are affected by CVE-2024-39347?
CVE-2024-39347 affects Synology Router Manager versions before 1.2.5-8227-11 and 1.3.1-9346-8.
What is the nature of the vulnerability described in CVE-2024-39347?
CVE-2024-39347 is an incorrect default permissions vulnerability in the firewall functionality of Synology Router Manager.