CVE-2024-45539

Published Dec 4, 2025

Last updated 3 months ago

Overview

Description
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.
Source
security@synology.com
NVD status
Analyzed
Products
diskstation_manager, diskstation_manager_unified_controller

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security@synology.com
CWE-787

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.