CVE-2024-5401: High severity Synology Diskstation Manager vulnerability
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5401?
CVE-2024-5401 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to gain elevated privileges.
How do I fix CVE-2024-5401?
To resolve CVE-2024-5401, users should update their Synology DiskStation Manager to versions 7.1.1-42962-8 or 7.2.1-69057-2 and 7.2.2-72806 or update Synology Unified Controller to version 3.1.4-23079.
Who is affected by CVE-2024-5401?
CVE-2024-5401 affects users of Synology DiskStation Manager versions prior to 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806, as well as Synology Unified Controller prior to 3.1.4-23079.
What type of vulnerability is CVE-2024-5401?
CVE-2024-5401 is an improper control of dynamically-managed code resources vulnerability.
Can remote users exploit CVE-2024-5401?
Yes, remote authenticated users can exploit CVE-2024-5401 to obtain unauthorized privileges.