Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syncology
Syncology replication Service Synology Synology diskstation Manager Synology diskstation Manager Unified Controller Synology replication Service Synology unified Controller |
|
| CPEs | cpe:2.3:a:syncology:replication_service:*:*:*:*:*:*:*:* cpe:2.3:a:synology:diskstation_manager_unified_controller:3.1:*:*:*:*:*:*:* cpe:2.3:a:synology:replication_service:*:*:*:*:*:*:*:* cpe:2.3:a:synology:unified_controller:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Syncology
Syncology replication Service Synology Synology diskstation Manager Synology diskstation Manager Unified Controller Synology replication Service Synology unified Controller |
Wed, 19 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Mar 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors. | |
| Weaknesses | CWE-193 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2025-03-19T14:13:16.719Z
Reserved: 2024-10-28T02:29:33.711Z
Link: CVE-2024-10442
Updated: 2025-03-19T14:13:07.139Z
Status : Analyzed
Published: 2025-03-19T03:15:11.790
Modified: 2026-01-16T16:50:48.027
Link: CVE-2024-10442
No data.