Without actually seeing what your firewall triggered on to give the alert the syn can be used for several things, one of which is a denial of service attacks(SYN Flooding).

The other could be an attempt to fingerprint your OS, I can't think of a time that it wouldn't be sent to a port. It could be your vendors way of generalizing the many malicious uses of a syn packet and just name the alert "SYN Port Attack"