ZDI-CAN-22460: ZDI-24-835: (Pwn2Own) Synology BC500 Protection Mechanism Failure Software Downgrade Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to downgrade Synology software on affected installations of Synology BC500 cameras. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2024-39352.
Affected Software
1 affected component
Synology BC500
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22460?
The CVSS rating for ZDI-CAN-22460 is 6.8, indicating a medium severity vulnerability.
2
How can I exploit ZDI-CAN-22460?
ZDI-CAN-22460 can be exploited by authenticated network-adjacent attackers to downgrade the software of affected Synology BC500 cameras.
3
What versions of Synology software are affected by ZDI-CAN-22460?
ZDI-CAN-22460 specifically affects installations of Synology BC500 cameras.
4
Are there any required permissions to exploit ZDI-CAN-22460?
Yes, authentication is required to exploit the ZDI-CAN-22460 vulnerability.
5
What type of vulnerability is ZDI-CAN-22460?
ZDI-CAN-22460 is classified as a software downgrade vulnerability.