CVE-2024-39350: High severity synology camera firmware vulnerability
A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39350?
CVE-2024-39350 has been rated as a critical vulnerability due to its potential for authentication bypass.
How do I fix CVE-2024-39350?
To fix CVE-2024-39350, upgrade to Synology Camera Firmware version 1.0.7-0298 or later.
Which devices are affected by CVE-2024-39350?
CVE-2024-39350 affects Synology camera models running firmware versions prior to 1.0.7-0298.
What type of attack does CVE-2024-39350 enable?
CVE-2024-39350 enables man-in-the-middle attacks by allowing authentication bypass.
Is my system vulnerable to CVE-2024-39350?
If you are using Synology Camera Firmware versions before 1.0.7-0298, your system is vulnerable to CVE-2024-39350.