ZDI-CAN-22311: ZDI-24-834: (Pwn2Own) Synology BC500 Improper Compartmentalization Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Synology BC500 cameras. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39350.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22311?
The severity of ZDI-CAN-22311 is high due to the potential for local privilege escalation on affected Synology BC500 cameras.
How do I fix ZDI-CAN-22311?
To fix ZDI-CAN-22311, ensure that your Synology BC500 camera firmware is updated to the latest version provided by Synology.
Who is affected by ZDI-CAN-22311?
ZDI-CAN-22311 affects installations of Synology BC500 cameras with vulnerabilities that allow local privilege escalation.
What type of attack leverages ZDI-CAN-22311?
ZDI-CAN-22311 can be exploited by local attackers who have already gained low-privileged access to the Synology BC500 camera.
What are the potential impacts of exploiting ZDI-CAN-22311?
Exploiting ZDI-CAN-22311 could allow an attacker to escalate their privileges, potentially compromising the security of the affected camera.