CVE-2024-47272
Description
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An incorrect authorization flaw in the IO Module of Synology Surveillance Station allows remote authenticated administrators to write limited files, posing a low-severity integrity risk.
Vulnerability
An incorrect authorization vulnerability exists in the IO Module functionality of Synology Surveillance Station, as described in advisory Synology_SA_24_25 [1]. This flaw affects versions before 9.2.2-11575 (for DSM 7.2 and 7.1) and before 9.2.2-9575 (for DSM 6.2) [1]. The issue arises from improper authorization checks, allowing remote authenticated users with administrator privileges to write files under unspecified conditions within the IO Module [1].
Exploitation
Exploitation requires a remote attacker to have valid administrator credentials and network access to the Surveillance Station instance [1]. The exact sequence of steps is not disclosed by Synology, and the vector is limited to file write operations under unspecified vectors within the IO Module [1]. No user interaction beyond authentication is required.
Impact
Successful exploitation leads to limited file write access for an authenticated administrator, which could be used to modify certain system or configuration files within the affected product [1]. The severity is rated Low with a CVSS v3 base score of 2.7, reflecting the high privileges required and the limited scope of the write capability. The primary impact is on the integrity of the system, though the exact scope of writable files is not specified.
Mitigation
Synology has released fixed versions: upgrade to version 9.2.2-11575 or above for DSM 7.2 and 7.1, and to version 9.2.2-9575 or above for DSM 6.2 [1]. The advisory states “Mitigation: None” [1], indicating no workaround is available; users should apply the patch promptly.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <9.2.2-11575 & <9.2.2-9575
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.