CVE-2024-50629
massUnauthenticated limited file-read in Synology DSM and BeeStation OS webapi
CVE-2024-50629 is an improper output encoding/escaping flaw (CWE-116) in the webapi component of Synology DiskStation Manager (DSM) and Synology BeeStation OS (BSM). A remote, unauthenticated attacker can trigger it over the network via unspecified vectors and read limited files on the device, with confidentiality impact only. It affects DSM builds prior to the fixed releases in each branch and BeeStation OS prior to 1.1-65374. No public proof-of-concept is known and the flaw is not yet in CISA KEV, but EPSS assigns a 29.1% probability of exploitation within 30 days (98th percentile), signaling elevated near-term risk. Given the very large installed base of internet-reachable Synology NAS devices, exposure could be significant even though impact is limited to file disclosure.
What to do: Upgrade BeeStation OS to 1.1-65374 or later, and upgrade DSM to the fixed build for your branch: 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6, or 7.2.2-72806-1. Until patched, restrict the DSM web interface and webapi (typically ports 5000/5001) to trusted networks via firewall or VPN and review logs for unauthenticated webapi access.
| Synology BeeStation OS (BSM) | all versions before 1.1-65374 |
| Synology DiskStation Manager (DSM) | all versions before 7.1.1-42962-7, before 7.2-64570-4, before 7.2.1-69057-6, and before 7.2.2-72806-1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.
- Vendors
- synology
- Products
- beestation os, diskstation manager
- Weakness
- CWE-116
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.