ZeroHour

CVE-2024-50629

mass

Unauthenticated limited file-read in Synology DSM and BeeStation OS webapi

CVSS 3.1
5.3 medium
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2024-50629 is an improper output encoding/escaping flaw (CWE-116) in the webapi component of Synology DiskStation Manager (DSM) and Synology BeeStation OS (BSM). A remote, unauthenticated attacker can trigger it over the network via unspecified vectors and read limited files on the device, with confidentiality impact only. It affects DSM builds prior to the fixed releases in each branch and BeeStation OS prior to 1.1-65374. No public proof-of-concept is known and the flaw is not yet in CISA KEV, but EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), signaling elevated near-term risk. Given the very large installed base of internet-reachable Synology NAS devices, exposure could be significant even though impact is limited to file disclosure.

What to do: Upgrade BeeStation OS to 1.1-65374 or later, and upgrade DSM to the fixed build for your branch: 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6, or 7.2.2-72806-1. Until patched, restrict the DSM web interface and webapi (typically ports 5000/5001) to trusted networks via firewall or VPN and review logs for unauthenticated webapi access.

Affected
Synology BeeStation OS (BSM)all versions before 1.1-65374
Synology DiskStation Manager (DSM)all versions before 7.1.1-42962-7, before 7.2-64570-4, before 7.2.1-69057-6, and before 7.2.2-72806-1
Estimated exposure
massseveral hundred thousand internet-exposed Synology NAS devices (millions deployed overall); subset with webapi reachable — Synology DSM is one of the most widely deployed NAS platforms with millions of units in the field, and public internet scans (e.g., Shodan) routinely index several hundred thousand exposed DSM web interfaces, though only devices with the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.

Vendors
synology
Products
beestation os, diskstation manager
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.