10
CVSSv3

CVE-2024-10442

CVSSv4: NA | CVSSv3: 10 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00279 | KEV: Not Included
Published: 19/03/2025 Updated: 19/03/2025

Vulnerability Summary

Synology Replication Service and DSMUC Off-by-One Remote Code Execution Vulnerability

An off-by-one error vulnerability exists in Synology Replication Service versions before 1.0.12-0066, 1.2.2-0353, and 1.3.0-0423, as well as in Synology Unified Controller (DSMUC) versions before 3.1.4-23079. This vulnerability in the transmission component could allow remote attackers to execute arbitrary code through unspecified attack vectors. The flaw may potentially enable attackers to compromise the system more extensively, presenting a significant security risk for users of these Synology products.

Vulnerability Trend

Github Repositories

This exploit was successfully submitted during Pwn2Own Ireland 2024 against the Synology DiskStation DS1823xs+ A blog post covers the details of the exploit The bug was assigned CVE-2024-10442 Synology's advisory can be found here