CRITICAL · 9.8

CVE-2024-39349

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote at...

Vulnerability Description

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SynologyBc500 Firmware< 1.0.7-0298
SynologyBc500-
SynologyTc500 Firmware< 1.0.7-0298
SynologyTc500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-39349?

CVE-2024-39349 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote at...

How severe is CVE-2024-39349?

CVE-2024-39349 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-39349?

Check the references section above for vendor advisories and patch information. Affected products include: Synology Bc500 Firmware, Synology Bc500, Synology Tc500 Firmware, Synology Tc500.