Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-10445

CVE-2024-10445: Synology BeeStation OS Certificate Vulnerability

CVE-2024-10445 is an improper certificate validation flaw in Synology BeeStation OS update functionality that enables unauthorized file writes. This article covers technical details, affected versions, and mitigation steps.

Updated:

CVE-2024-10445 Overview

CVE-2024-10445 is an improper certificate validation vulnerability [CWE-295] affecting the update functionality in Synology BeeStation OS (BSM) and Synology DiskStation Manager (DSM). The flaw allows remote attackers to write limited files through unspecified vectors by bypassing certificate checks during the update process. Synology assigned the issue medium severity and addressed it across multiple DSM release branches and BeeStation OS.

The vulnerability affects network-based update flows, meaning attackers positioned to intercept traffic can leverage the weak validation to influence what the device accepts as a legitimate update artifact.

Critical Impact

Remote attackers can write limited files to affected Synology storage devices by exploiting weak certificate validation in the update path, undermining the integrity of the update mechanism.

Affected Products

  • Synology BeeStation OS (BSM) before 1.1-65374
  • Synology DiskStation Manager (DSM) 6.2 before 6.2.4-25556-8, DSM 7.1 before 7.1.1-42962-7, DSM 7.2 before 7.2-64570-4
  • Synology DSM 7.2.1 before 7.2.1-69057-6 and DSM 7.2.2 before 7.2.2-72806-1

Discovery Timeline

  • 2025-03-19 - CVE-2024-10445 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-10445

Vulnerability Analysis

The vulnerability resides in the update functionality of Synology BeeStation OS and DiskStation Manager. The affected code path fails to properly validate the TLS certificate presented by the update endpoint. As a result, an attacker able to intercept or redirect update traffic can deliver content that the device treats as trusted.

The consequence is limited file write on the target appliance. Exploitation does not require authentication or user interaction, but the write primitive is constrained, which aligns with the low integrity impact and no confidentiality or availability impact recorded by Synology.

EPSS scoring places the probability of observed exploitation at 0.365% (29.4 percentile), and no public proof-of-concept, exploit code, or CISA KEV listing is currently associated with the CVE.

Root Cause

The update client on affected Synology firmware performs insufficient verification of the X.509 certificate chain presented during update retrieval. Certificate validation weaknesses in [CWE-295] typically include skipping hostname checks, accepting expired or self-signed certificates, or trusting untrusted certificate authorities. Synology's advisories confirm the update path treats improperly validated responses as authoritative, enabling attacker-controlled data to reach file write operations.

Attack Vector

An attacker with a network position between the Synology device and the update infrastructure can present a rogue TLS endpoint. Because the client does not enforce strict certificate validation, the device accepts attacker-supplied update content and performs a limited file write. Suitable positions include compromised upstream network devices, malicious Wi-Fi, DNS hijacking, or on-path adversary attacks targeting the update domain.

No verified public exploitation code is available. Refer to the Synology Security Advisory SA-24-20 and Synology Security Advisory SA-24-23 for vendor-supplied technical detail.

Detection Methods for CVE-2024-10445

Indicators of Compromise

  • Unexpected outbound TLS sessions from Synology appliances to hosts that are not official Synology update endpoints.
  • Update-related file writes on the appliance that do not correspond to a scheduled or administrator-initiated update.
  • DNS resolution anomalies for Synology update domains, including unexpected IP addresses or short TTLs.
  • Presence of untrusted or self-signed certificates in captured TLS handshakes from the device.

Detection Strategies

  • Inspect egress traffic from BeeStation and DSM devices at the network boundary and compare TLS server certificates against known-good Synology issuer chains.
  • Alert on Synology devices communicating with non-Synology destinations on TCP/443 during update windows.
  • Correlate firmware version telemetry with vendor-published fixed versions to identify devices still exposed.

Monitoring Recommendations

  • Log DNS queries from storage appliances and flag deviations from historical Synology update domains.
  • Monitor firmware version changes across the fleet and validate them against Synology's published release notes.
  • Ingest network and appliance logs into a centralized analytics platform to identify anomalous update behavior across multiple devices.

How to Mitigate CVE-2024-10445

Immediate Actions Required

  • Upgrade BeeStation OS to 1.1-65374 or later and DSM to the fixed release matching the installed branch: 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6, or 7.2.2-72806-1.
  • Inventory all Synology appliances and confirm firmware versions against the vendor advisories.
  • Restrict outbound network access from storage appliances to known Synology update endpoints only.

Patch Information

Synology has released fixed firmware for all affected products. See the Synology Security Advisory SA-24-20 and Synology Security Advisory SA-24-23 for the complete list of fixed versions and release notes. Apply updates through DSM Control Panel or BeeStation's management interface.

Workarounds

  • Where immediate patching is not feasible, block the appliance from initiating outbound connections except to verified Synology update infrastructure.
  • Place BeeStation and DSM devices behind a network segment that enforces strict egress filtering and TLS inspection.
  • Disable automated update checks until the firmware has been upgraded to a fixed version and validated.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.