Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2024-47
Version:
1.0
Affected software:
Synology Surveillance Station for DSM versions 9.2.0-11289
Synology Surveillance Station for DSM versions 9.2.0-9289
Type:
Missing authorization vulnerability in System webapi component
CVE/CVSS:
CVE-2024-29241
CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H)
Synology Surveillance Station is a surveillance solution with video monitoring, management, and analysis tools.
Exploitation of recently disclosed CVE-2024-29241 could have an impact on the integrity and availability of (data on) the system. Remote users have to be authenticated. No information is available whether or not the flaw is actively exploited. A patch is available.
A missing authorization vulnerability in the System webapi component in the affected Synology Surveillance Station software allows bypass of security constraints via unspecified vectors.
Patch
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.
Monitor/Detect
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via: https://ccb.belgium.be/cert/report-incident
While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.