Executive brief
Synology BeeDrive for desktop is a backup and file synchronization application for personal storage devices. A security flaw in its internal database component allows a local user on the computer to access restricted files or directories. This could be exploited to crash the service, leading to a denial-of-service where the user can no longer sync or back up their data.
Technical details
A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in the redis-server component of Synology BeeDrive for desktop before version 1.3.2-13814. The flaw stems from improper access controls on files or directories used by the internal Redis instance. A local attacker with access to the host system can exploit this to interfere with the service's operations, leading to a denial-of-service (DoS) condition. The attack vector is local, requiring no special privileges or user interaction. Users are advised to upgrade to version 1.3.2-13814 or later to remediate the issue.
Affected products
- Synology BeeDrive for desktop before 1.3.2-13814
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory SA_24_26
- 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published