CVE-2024-5401

Source
https://cve.org/CVERecord?id=CVE-2024-5401
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5401.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5401
Published
2025-12-04T15:15:54.733Z
Modified
2026-03-12T14:40:18.112874Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote authenticated users to obtain privileges without consent via unspecified vectors.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "7.2.1-69057"
            },
            {
                "fixed": "7.2.1-69057-2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.2-72803"
            },
            {
                "fixed": "7.2.2-72806"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "3.1-23028"
            },
            {
                "fixed": "3.1.4-23079"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5401.json"