CVE-2024-45539
7.5Synology · DiskStation Manager (DSM) and Unified Controller (DSMUC)
An out-of-bounds write vulnerability in Synology DiskStation Manager (DSM) and Unified Controller (DSMUC) allows remote, unauthenticated attackers to cause a denial-of-service condition.
Executive summary
A critical out-of-bounds write vulnerability in Synology DSM and DSMUC software enables remote, unauthenticated attackers to crash affected systems, resulting in a denial-of-service.
Vulnerability
The flaw is categorized as an out-of-bounds write (CWE-787) occurring within the cgi components of the affected software. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates this can be exploited by an unauthenticated remote attacker without requiring user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high severity due to the ease of exploitation. Successful exploitation leads to a denial-of-service, which can cause significant operational disruption by rendering storage services and management interfaces unavailable to users and business processes.
Remediation
Immediate Action: Apply the vendor-provided updates by upgrading DSM to version 7.2.2-72806 or 7.2.1-69057-2, and DSMUC to version 3.1.4-23079 as specified in the Synology security advisory.
Proactive Monitoring: Monitor system logs for repeated service crashes or unexpected process terminations involving cgi components that may indicate an attempt to trigger this vulnerability.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter malicious requests directed at the management interface, and restrict network access to the DSM administration port to trusted IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote disruption, organizations running Synology DSM or DSMUC should prioritize the installation of the provided firmware updates. Ensure that all storage appliances are included in regular patching cycles to mitigate the risk of denial-of-service attacks against critical infrastructure.
More Synology CVEs
Sources
Originally found and disclosed by Steven Lin ( https://x.com/5teven1in ), per the CVE Program record.
- Synology-SA-24:27 DSM Vendor advisory