CVE-2024-39348: High severity synology router manager vulnerability
Published Jun 28, 2024
·Updated
Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.
Affected Software
22 affected components
Synology Router Manager<1.2.5-8227-11, <1.3.1-9346-8
Synology Router Manager>=1.2<1.2.5-8227
Synology Router Manager>=1.3<1.3.1-9346
Synology Router Manager=1.2.5-8227
Synology Router Manager=1.2.5-8227-update1
Synology Router Manager=1.2.5-8227-update10
Synology Router Manager=1.2.5-8227-update2
Synology Router Manager=1.2.5-8227-update3
Synology Router Manager=1.2.5-8227-update4
Synology Router Manager=1.2.5-8227-update5
Synology Router Manager=1.2.5-8227-update6
Synology Router Manager=1.2.5-8227-update7
Synology Router Manager=1.2.5-8227-update8
Synology Router Manager=1.2.5-8227-update9
Synology Router Manager=1.3.1-9346
Synology Router Manager=1.3.1-9346-update1
Synology Router Manager=1.3.1-9346-update2
Synology Router Manager=1.3.1-9346-update3
Synology Router Manager=1.3.1-9346-update4
Synology Router Manager=1.3.1-9346-update5
Synology Router Manager=1.3.1-9346-update6
Synology Router Manager=1.3.1-9346-update7
Event History
Jun 28, 2024
CVE Published
via MITRE·06:30 AM
Data Sourced
via MITRE·06:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39348?
CVE-2024-39348 is classified as a medium severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-39348?
To fix CVE-2024-39348, update your Synology Router Manager to version 1.2.5-8227-11 or 1.3.1-9346-8 or later.
3
What type of attack does CVE-2024-39348 expose users to?
CVE-2024-39348 exposes users to man-in-the-middle attacks that can allow the execution of arbitrary code.
4
What versions of Synology Router Manager are affected by CVE-2024-39348?
CVE-2024-39348 affects Synology Router Manager versions prior to 1.2.5-8227-11 and 1.3.1-9346-8.
5
Is there a patch available for CVE-2024-39348?
Yes, a patch is available in the form of software updates for Synology Router Manager.