Junglewise Threat Intelligence

CVE-2024-47270: Synology Surveillance Station improper preservation of permissions in Archiving Push

CVE-2024-47270 · Severity: low · CVSS 2.7 · Published 2026-05-27

Technologies: Synology Surveillance Station. Vendors: Synology.

Executive brief

Synology Surveillance Station, a video management system used for managing IP cameras and security recordings, contains a vulnerability in its Archiving Push feature. This flaw allows a remote user who already has administrator-level access to write to certain files they should not normally be able to modify. While the impact is limited because it requires high-level permissions, it could potentially be used to bypass intended security restrictions or alter system configurations.

Technical details

An improper preservation of permissions vulnerability (CWE-281) exists in the Archiving Push functionality of Synology Surveillance Station. The flaw allows a remote authenticated attacker with administrator privileges to perform limited file writes via unspecified vectors. The vulnerability stems from the application failing to correctly maintain or enforce permission boundaries during archiving operations. This issue is resolved in Surveillance Station versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).

Affected products

  • Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575

Timeline

  • 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
  • 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published to NVD

References

Related threats