By LBT Technology Group, LLC. on Friday, 08 November 2024
Category: Security

Zero-click flaw in Synology NAS devices

Threat update

​Synology, network-attached storage (NAS) maker, addressed critical security vulnerability, CVE-2024-10443, which impacts their DiskStation and BeePhotos applications. This is an unauthenticated vulnerability that can allow attackers to obtain root-level code execution on Synology NAS devices.

Technical Detail and Additional Info

What is the threat?

​CVE-2024-10443 is a zero-click vulnerability which enables attackers to gain access to devices and steal data or plant malware without user interaction. Once exploited, a malicious actor will have full access to the system and can turn the affected device into a botnet to further attack other infrastructures.

Why is it noteworthy?

​As this is a zero-click vulnerability in which no user interaction is required, threat actors can easily exploit this vulnerability to gain access to the system, steal personal and corporate files, plant backdoors, or infect the system with ransomware. The SynologyPhotos app is enabled by default on BeeStation storage devices. It is also used in their DiskStation storage systems.

What is the exposure or risk?

​The flaw affects the following Synology versions:


Additionally, because the affected applications come pre-installed with the devices, all Synology users are at risk. NAS devices are considered high-value targets for ransomware operators since they store large amounts of data. In addition, many users connect them directly to the internet. While the systems can be set up with a gateway requiring credentials, the part of the photo app that contains the zero-click vulnerability does not require authentication.

What are the recommendations?

 LBT Technology Group recommends the following actions to secure your NAS devices against this threat:

References

 For more in-depth information about the recommendations, please visit the following links:

If you have any questions, please contact LBT's Sales Engineer.

Related Posts

Leave Comments