Synology
Synology Surveillance Station: vulnerabilidades y CVE
Synology Surveillance Station tiene 25 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-47272 | Baja (2.7) | 0.25% | — | 27 may 2026 | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write… |
| CVE-2024-47271 | Media (4.9) | 0.34% | — | 27 may 2026 | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain… |
| CVE-2024-47270 | Baja (2.7) | 0.25% | — | 27 may 2026 | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to… |
| CVE-2024-47269 | Media (4.9) | 0.23% | — | 27 may 2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator… |
| CVE-2024-47268 | Media (4.9) | 0.34% | — | 27 may 2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive… |
| CVE-2024-47267 | Baja (2.7) | 0.33% | — | 27 may 2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated… |
| CVE-2023-52944 | Media (4.3) | 0.40% | — | 4 dic 2024 | Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action… |
| CVE-2023-52943 | Media (4.3) | 0.40% | — | 4 dic 2024 | Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting… |
| CVE-2024-29241 | Crítica (9.9) | 0.76% | — | 28 mar 2024 | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive… |
| CVE-2024-29240 | Media (4.3) | 0.68% | — | 28 mar 2024 | Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via… |
| CVE-2024-29239 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows… |
| CVE-2024-29238 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote… |
| CVE-2024-29237 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote… |
| CVE-2024-29236 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote… |
| CVE-2024-29235 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote… |
| CVE-2024-29234 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote… |
| CVE-2024-29233 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote… |
| CVE-2024-29232 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote… |
| CVE-2024-29231 | Media (5.4) | 0.65% | — | 28 mar 2024 | Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive… |
| CVE-2024-29230 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows… |
| CVE-2024-29229 | Alta (7.7) | 0.80% | — | 28 mar 2024 | Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via… |
| CVE-2024-29228 | Alta (7.7) | 0.80% | — | 28 mar 2024 | Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified… |
| CVE-2024-29227 | Media (5.4) | 0.59% | — | 28 mar 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote… |
| CVE-2017-16770 | Media (6.5) | 1.8% | — | 27 feb 2018 | File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's… |
| CVE-2017-16767 | Media (5.4) | 1.0% | — | 27 feb 2018 | Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter. |