ZDI-24-836: (Pwn2Own) Synology BC500 update_ntp_config Command Injection Remote Code Execution Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BC500 IP cameras. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.
Affected Software
1 affected component
Synology BC500
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-836?
The severity of ZDI-24-836 is rated at CVSS 6.8.
2
How do I fix ZDI-24-836?
To fix ZDI-24-836, update your Synology BC500 IP camera to the latest firmware version provided by the vendor.
3
Who can exploit the ZDI-24-836 vulnerability?
Network-adjacent attackers can exploit the ZDI-24-836 vulnerability, but authentication is required.
4
What type of vulnerability is ZDI-24-836?
ZDI-24-836 is a remote code execution vulnerability affecting Synology BC500 IP cameras.
5
What are the potential impacts of ZDI-24-836?
The potential impacts of ZDI-24-836 include unauthorized access and arbitrary code execution on the affected devices.