nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-4464 CVE-2024-4464
HIGH
Record summary
CVE-2024-4464 has a selected CVSS score of 7.5 (high).
Description
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Media ServerBrowse Synology / Media ServerDefault status: affected | CVE List | * to < 2.0.5-3152 | affected |
| * to < 2.2.0-3325 | affected | ||
| * to < 1.4-2680 | affected |
References
2Synology-SA-24:28 Media ServerVendor advisory
https://www.synology.com/en-global/security/advisory/Synology_SA_24_28