CVE-2024-47271
Insufficient Credential Protection in Synology Surveillance Station
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: Synology Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| synology | surveillance_station | to 9.2.2-9575 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an insufficiently protected credentials issue in the IPSpeaker component of Synology Surveillance Station versions before 9.2.2-11575 and 9.2.2-9575. It allows remote authenticated users who have administrator privileges to obtain sensitive information through unspecified methods.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker with administrator access can remotely obtain sensitive information from the system. This could lead to exposure of confidential data, potentially compromising system security and privacy.