CVE-2024-10442
CRITICALDescription
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| synology | unified_controller |
| synology | diskstation_manager_unified_controller |
| synology | replication_service |
| synology | diskstation_manager |
| synology | replication_service |
| synology | diskstation_manager |
| syncology | replication_service |
| synology | diskstation_manager |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-10442? +
How severe is CVE-2024-10442? +
What products are affected by CVE-2024-10442? +
How do I check if I'm vulnerable to CVE-2024-10442? +
Related Vulnerabilities
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName …
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: ABB …
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for …
An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled …
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix off-by-one in CMA heap fault handler Until …
In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix off-by-one error in sd_read_block_characteristics() Ff the device …