Cyber Posture

CVE-2024-10444

High

Published: 19 March 2025

Published
19 March 2025
Modified
17 November 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0027 49.9th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.

Security Summary

CVE-2024-10444 is an improper certificate validation vulnerability (CWE-295) affecting the LDAP utilities in Synology DiskStation Manager (DSM) versions prior to 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3. This flaw enables man-in-the-middle (MITM) attackers to hijack administrator authentication through unspecified vectors, as disclosed on March 19, 2025. The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high potential impact on confidentiality, integrity, and availability.

The attack requires a network-accessible position for MITM interception, high attack complexity, no user privileges, and user interaction, such as an administrator triggering the vulnerable LDAP operation. Successful exploitation allows attackers to impersonate administrators, potentially granting unauthorized access to DSM administrative functions and compromising the entire DiskStation system.

Synology's security advisory (Synology_SA_25_01) details the issue and recommends updating to DSM 7.1.1-42962-8, 7.2.1-69057-7, or 7.2.2-72806-3, or later, to mitigate the vulnerability by addressing the certificate validation flaw in LDAP utilities.

Details

CWE(s)
CWE-295

Affected Products

synology
diskstation manager
7.1 — 7.1.1-42962-8 · 7.2.1-69057 — 7.2.1-69057-7 · 7.2.2 — 7.2.2-72806-3

MITRE ATT&CK Enterprise Techniques

T1557 Adversary-in-the-Middle Credential Access
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.
Why these techniques?

The vulnerability's improper certificate validation in LDAP utilities directly enables MITM attackers to intercept and hijack administrator authentication sessions.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References