Vulnerability Description
A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Bc500 Firmware | < 1.1.1-0383 |
| Synology | Bc500 | - |
| Synology | Tc500 Firmware | < 1.1.1-0383 |
| Synology | Tc500 | - |
Related Weaknesses (CWE)
References
- https://www.synology.com/en-global/security/advisory/Synology_SA_24_07Vendor Advisory
- https://www.synology.com/en-global/security/advisory/Synology_SA_24_07Vendor Advisory
FAQ
What is CVE-2024-5463?
CVE-2024-5463 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files contain...
How severe is CVE-2024-5463?
CVE-2024-5463 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5463?
Check the references section above for vendor advisories and patch information. Affected products include: Synology Bc500 Firmware, Synology Bc500, Synology Tc500 Firmware, Synology Tc500.