CVE-2024-50629
19.03.2025, 06:15
Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| synology | beestation_os | 1.0 |
| synology | beestation_os | 1.0:65145 |
| synology | beestation_os | 1.0:65149 |
| synology | beestation_os | 1.0:65162 |
| synology | beestation_os | 1.0.1:65210 |
| synology | beestation_os | 1.0.2:65233 |
| synology | beestation_os | 1.0.2:65235 |
| synology | beestation_os | 1.1 |
| synology | beestation_os | 1.1:65373 |
| synology | diskstation_manager | 7.1 ≤ 𝑥 < 7.1.1-42962-7 |
| synology | diskstation_manager | 7.2 ≤ 𝑥 < 7.2-64570-4 |
| synology | diskstation_manager | 7.2.1-69057 ≤ 𝑥 < 7.2.1-69057-6 |
| synology | diskstation_manager | 7.2.2 ≤ 𝑥 < 7.2.2-72806-1 |
𝑥
= Vulnerable software versions