ZDI-24-835: (Pwn2Own) Synology BC500 Protection Mechanism Failure Software Downgrade Vulnerability
This vulnerability allows network-adjacent attackers to downgrade Synology software on affected installations of Synology BC500 cameras. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2024-39352.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-835?
The CVSS rating for ZDI-24-835 is 6.8, indicating a medium severity vulnerability.
How do I fix ZDI-24-835?
To mitigate ZDI-24-835, ensure that your Synology BC500 cameras are updated to the latest firmware version provided by Synology.
Who can exploit the ZDI-24-835 vulnerability?
Network-adjacent attackers can exploit the ZDI-24-835 vulnerability, as authentication is required.
What is the impact of ZDI-24-835?
ZDI-24-835 allows attackers to downgrade the Synology software on affected BC500 cameras.
Is authentication required for ZDI-24-835 exploitation?
Yes, authentication is required to exploit the ZDI-24-835 vulnerability.