MEDIUM · 6.5

CVE-2024-5463

A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files contain...

Vulnerability Description

A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
SynologyBc500 Firmware< 1.1.1-0383
SynologyBc500-
SynologyTc500 Firmware< 1.1.1-0383
SynologyTc500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-5463?

CVE-2024-5463 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to write specific files contain...

How severe is CVE-2024-5463?

CVE-2024-5463 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-5463?

Check the references section above for vendor advisories and patch information. Affected products include: Synology Bc500 Firmware, Synology Bc500, Synology Tc500 Firmware, Synology Tc500.