CVE-2024-39347

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
synologyCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
synologyrouter_manager
1.2 ≤
𝑥
< 1.2.5-8227
synologyrouter_manager
1.3 ≤
𝑥
< 1.3.1-9346
synologyrouter_manager
1.2.5-8227
synologyrouter_manager
1.2.5-8227:update1
synologyrouter_manager
1.2.5-8227:update10
synologyrouter_manager
1.2.5-8227:update2
synologyrouter_manager
1.2.5-8227:update3
synologyrouter_manager
1.2.5-8227:update4
synologyrouter_manager
1.2.5-8227:update5
synologyrouter_manager
1.2.5-8227:update6
synologyrouter_manager
1.2.5-8227:update7
synologyrouter_manager
1.2.5-8227:update8
synologyrouter_manager
1.2.5-8227:update9
synologyrouter_manager
1.3.1-9346
synologyrouter_manager
1.3.1-9346:update1
synologyrouter_manager
1.3.1-9346:update2
synologyrouter_manager
1.3.1-9346:update3
synologyrouter_manager
1.3.1-9346:update4
synologyrouter_manager
1.3.1-9346:update5
synologyrouter_manager
1.3.1-9346:update6
synologyrouter_manager
1.3.1-9346:update7
𝑥
= Vulnerable software versions