CVE-2024-11131
CRITICALSynology Bc500 Firmware < 1.2.0-0525 - Out-of-Bounds Read
Title source: ruleDescription
A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.synology.com/en-global/security/advisory/Synology_SA_24_24
Scores
CVSS v3
9.8
EPSS
0.0933
EPSS Percentile
92.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-125
Status
published
Products (3)
synology/bc500_firmware
< 1.2.0-0525
synology/cc400w_firmware
< 1.2.0-0525
synology/tc500_firmware
< 1.2.0-0525
Published
Mar 19, 2025
Tracked Since
Feb 18, 2026