CVE-2024-45538: CSRF
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45538?
CVE-2024-45538 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2024-45538?
To mitigate CVE-2024-45538, upgrade Synology DiskStation Manager to version 7.2.1-69057-2 or later, and Synology Unified Controller to version 3.1.4-23079 or later.
What systems are affected by CVE-2024-45538?
CVE-2024-45538 affects Synology DiskStation Manager versions before 7.2.1-69057-2 and 7.2.2-72806, as well as Synology Unified Controller versions before 3.1.4-23079.
What type of vulnerability is CVE-2024-45538?
CVE-2024-45538 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2024-45538 be exploited remotely?
Yes, CVE-2024-45538 can be exploited remotely by attackers to execute arbitrary code.