CVE-2024-4464: High severity Synology Media Server vulnerability
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4464?
CVE-2024-4464 has been rated as a high severity vulnerability due to its potential for authorization bypass and unauthorized file access.
How do I fix CVE-2024-4464?
To mitigate CVE-2024-4464, update Synology Media Server to version 1.4-2681, 2.0.5-3153, or 2.2.0-3326 or later.
Which versions of Synology Media Server are affected by CVE-2024-4464?
CVE-2024-4464 affects Synology Media Server versions prior to 1.4-2680, 2.0.5-3152, and 2.2.0-3325.
What types of attacks are possible with CVE-2024-4464?
CVE-2024-4464 allows remote attackers to read specific files through an authorization bypass mechanism.
Is there a known exploitation method for CVE-2024-4464?
The specific vectors for exploiting CVE-2024-4464 have not been disclosed, but the vulnerability facilitates unauthorized file reading.