CVE-2024-29234

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
OR cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*

History

04 Aug 2025, 19:08

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 5.4

01 Aug 2025, 05:15

Type Values Removed Values Added
Summary Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.

14 Jan 2025, 20:24

Type Values Removed Values Added
CPE cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
References () https://www.synology.com/en-global/security/advisory/Synology_SA_24_04 - () https://www.synology.com/en-global/security/advisory/Synology_SA_24_04 - Vendor Advisory
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Synology
Synology surveillance Station
Synology diskstation Manager

28 Mar 2024, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-28 07:16

Updated : 2025-08-04 19:08


NVD link : CVE-2024-29234

Mitre link : CVE-2024-29234


JSON object : View

Products Affected

synology

  • diskstation_manager
  • surveillance_station
CWE

No CWE.