Description
A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers to read specific files containing non-sensitive information via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51898 | A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers to read specific files containing non-sensitive information via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500. |
References
History
Tue, 04 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology bc500 Synology bc500 Firmware Synology tc500 Synology tc500 Firmware |
|
| CPEs | cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:* cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:* cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology
Synology bc500 Synology bc500 Firmware Synology tc500 Synology tc500 Firmware |
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2024-08-02T21:16:43.667Z
Reserved: 2023-11-10T07:59:45.608Z
Link: CVE-2023-47803
Updated: 2024-08-02T21:16:43.667Z
Status : Analyzed
Published: 2024-06-28T06:15:04.833
Modified: 2025-04-10T18:38:20.383
Link: CVE-2023-47803
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD