ZDI-CAN-22461: ZDI-24-836: (Pwn2Own) Synology BC500 update_ntp_config Command Injection Remote Code Execution Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BC500 IP cameras. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.
Affected Software
1 affected component
Synology BC500
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22461?
ZDI-CAN-22461 has a CVSS rating of 6.8, indicating a medium severity level.
2
How do I fix ZDI-CAN-22461?
To mitigate ZDI-CAN-22461, ensure that you update your Synology BC500 IP cameras to the latest firmware provided by Synology.
3
Who can exploit ZDI-CAN-22461?
ZDI-CAN-22461 can be exploited by network-adjacent attackers who have the proper authentication credentials.
4
What type of vulnerability is ZDI-CAN-22461?
ZDI-CAN-22461 is a code execution vulnerability in Synology BC500 IP cameras.
5
Is authentication required to exploit ZDI-CAN-22461?
Yes, authentication is required to successfully exploit the vulnerability identified by ZDI-CAN-22461.