ZDI-CAN-25487: ZDI-25-215: (Pwn2Own) Synology DiskStation DS1823xs+ LDAP Client Improper Certificate Validation Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Synology DiskStation DS1823xs+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-10444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25487?
ZDI-CAN-25487 has a CVSS rating of 7.5, indicating it is a high-severity vulnerability.
How do I fix ZDI-CAN-25487?
To fix ZDI-CAN-25487, ensure that you have applied the latest firmware updates provided by Synology for the DiskStation DS1823xs+.
Who is affected by ZDI-CAN-25487?
ZDI-CAN-25487 affects installations of Synology DiskStation DS1823xs+ devices that have not been patched.
What can an attacker do with ZDI-CAN-25487?
An attacker can bypass authentication on affected Synology DiskStation DS1823xs+ installations, allowing unauthorized access.
Is authentication needed to exploit ZDI-CAN-25487?
No, authentication is not required to exploit the ZDI-CAN-25487 vulnerability.