Description

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

INFO

Published Date :

2024-06-28T06:07:21.260Z

Last Modified :

2024-08-02T04:26:14.288Z

Source :

synology
AFFECTED PRODUCTS

The following products are affected by CVE-2024-39351 vulnerability.

Vendors Products
Synology
  • Bc500
  • Bc500 Firmware
  • Tc500
  • Tc500 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-39351.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact