Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-39350

CVE-2024-39350: Synology TC500 Auth Bypass Vulnerability

CVE-2024-39350 is an authentication bypass vulnerability in Synology TC500 firmware that allows man-in-the-middle attackers to gain unauthorized privileges. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-39350 Overview

CVE-2024-39350 is an authentication bypass by spoofing vulnerability in the Real Time Streaming Protocol (RTSP) functionality of Synology BC500 and TC500 network cameras. The flaw allows man-in-the-middle (MITM) attackers on an adjacent network to obtain privileges without user consent through unspecified vectors. Synology Camera Firmware versions before 1.0.7-0298 are affected. The weakness is categorized under CWE-290: Authentication Bypass by Spoofing.

Critical Impact

Successful exploitation lets an adjacent-network attacker impersonate a trusted RTSP peer, gaining unauthorized access to camera streams and administrative privileges without user interaction.

Affected Products

  • Synology BC500 camera (firmware before 1.0.7-0298)
  • Synology TC500 camera (firmware before 1.0.7-0298)
  • Synology BC500 and TC500 firmware images distributed prior to the fixed release

Discovery Timeline

  • 2024-06-28 - CVE-2024-39350 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-39350

Vulnerability Analysis

The vulnerability resides in the RTSP handling code of the BC500 and TC500 camera firmware. RTSP is used to negotiate and control media streams between clients and the camera. The implementation fails to sufficiently validate the identity of the communicating peer, allowing an attacker positioned between the client and camera to spoof a legitimate participant.

Because authentication is performed in a manner that can be replicated or replayed by a spoofing peer, the attacker can present themselves as an authorized entity. This yields access to protected RTSP resources and camera control functions without providing valid credentials. The advisory does not disclose specific spoofing vectors, but the CWE-290 classification confirms the root category.

Exploitation requires network adjacency, elevating complexity, but requires no user interaction and no prior privileges. Successful attacks compromise confidentiality, integrity, and availability of the camera and its live streams.

Root Cause

The RTSP service trusts session identifiers or authentication artifacts that can be observed or impersonated by an on-path attacker. The service does not bind session state to a cryptographically verified peer identity, which is the defining characteristic of CWE-290.

Attack Vector

An attacker on the same broadcast domain or an intermediate network segment intercepts RTSP negotiation traffic between an authorized client and the Synology camera. The attacker spoofs the trusted peer during session establishment and inherits the privileges granted to that peer. No credentials, phishing, or user action are required. Detailed exploitation vectors are not published by the vendor.

See the Synology Security Advisory Synology_SA_23_15 for vendor guidance.

Detection Methods for CVE-2024-39350

Indicators of Compromise

  • Unexpected RTSP DESCRIBE, SETUP, or PLAY requests from hosts that are not authorized video management systems
  • Duplicate RTSP session identifiers observed in packet captures between legitimate clients and cameras
  • Camera streams being retrieved from IP addresses outside of the documented VMS or NVR pool
  • Firmware version reporting below 1.0.7-0298 on BC500 or TC500 devices during asset inventory

Detection Strategies

  • Inspect network traffic on VLANs hosting IP cameras for ARP spoofing, rogue DHCP responses, or duplicate MAC-to-IP bindings that enable MITM positioning
  • Correlate RTSP session logs from the camera or NVR with expected client identities and alert on mismatches
  • Perform authenticated firmware version audits on all Synology BC500 and TC500 devices and flag any below 1.0.7-0298

Monitoring Recommendations

  • Enable syslog forwarding from Synology cameras and supporting NVRs to a centralized log platform for RTSP session review
  • Monitor for unauthorized clients establishing RTSP sessions on TCP port 554 or associated RTP/RTCP ports
  • Track configuration changes on camera devices, including new users, stream endpoints, or exported credentials

How to Mitigate CVE-2024-39350

Immediate Actions Required

  • Upgrade Synology BC500 and TC500 cameras to Synology Camera Firmware 1.0.7-0298 or later
  • Isolate IP cameras on a dedicated management VLAN with strict access control lists limiting RTSP clients
  • Disable RTSP on cameras where the protocol is not required by the video management system
  • Enforce switch-level protections such as Dynamic ARP Inspection and DHCP snooping to reduce MITM opportunities on adjacent networks

Patch Information

Synology has released fixed firmware in version 1.0.7-0298 for the BC500 and TC500 camera models. Refer to the Synology Security Advisory Synology_SA_23_15 for the authoritative fix guidance and download links.

Workarounds

  • Restrict RTSP access to a hardcoded allowlist of NVR or VMS IP addresses at the network firewall until patching is complete
  • Terminate RTSP streams inside a VPN tunnel or IPsec-protected segment so that spoofing an on-path peer is not feasible
  • Segment camera traffic away from user endpoints and guest networks to remove adjacent-network attackers from the broadcast domain

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.