CVE Published: 04/12/2024 |
CVE Updated: 04/12/2024 |
CVE Year: 2023 Source: synology |
Vendor: Synology |
Product: Surveillance Station Status : PUBLISHED
CVE-2023-52944 Description
Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N