Description
A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37913 | A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2024-08-02T04:26:14.798Z
Reserved: 2024-06-24T10:57:17.891Z
Link: CVE-2024-39350
Updated: 2024-08-02T04:26:14.798Z
Status : Awaiting Analysis
Published: 2024-06-28T07:15:06.330
Modified: 2024-11-21T09:27:31.610
Link: CVE-2024-39350
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD