First published: Fri Jun 28 2024(Updated: )
A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Camera Firmware | <1.0.7-0298 | |
All of | ||
Synology Camera Firmware | <1.0.7-0298 | |
Synology BC500 | ||
All of | ||
Synology Camera Firmware | <1.0.7-0298 | |
Synology TC500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39350 has been rated as a critical vulnerability due to its potential for authentication bypass.
To fix CVE-2024-39350, upgrade to Synology Camera Firmware version 1.0.7-0298 or later.
CVE-2024-39350 affects Synology camera models running firmware versions prior to 1.0.7-0298.
CVE-2024-39350 enables man-in-the-middle attacks by allowing authentication bypass.
If you are using Synology Camera Firmware versions before 1.0.7-0298, your system is vulnerable to CVE-2024-39350.