ZDI-24-833: (Pwn2Own) Synology BC500 synocam_param.cgi Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BC500 cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-39349.
Affected Software
1 affected component
Synology BC500
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-833?
The severity of ZDI-24-833 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-24-833?
To fix ZDI-24-833, update your Synology BC500 camera firmware to the latest version provided by the manufacturer.
3
Is authentication required to exploit ZDI-24-833?
No, authentication is not required to exploit ZDI-24-833.
4
What type of access do attackers gain with ZDI-24-833?
Attackers can execute arbitrary code on affected installations of Synology BC500 cameras due to ZDI-24-833.
5
What are the affected products for ZDI-24-833?
The affected product for ZDI-24-833 is the Synology BC500 camera.