ZeroHour

CVE-2024-50630

large

Unauthenticated admin credential disclosure in Synology Drive Server webapi

CVSS 3.1
7.5 high
EPSS
25%p98
Published
()
Modified
AI analysis

Synology Drive Server versions prior to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, and 3.5.1-26102 contain a missing-authentication flaw (CWE-306) in the webapi component. Because the affected API function requires no credentials, a remote attacker can reach it over the network without user interaction and, via unspecified vectors, obtain administrator credentials. Successful exploitation gives the attacker administrative credentials for the Drive Server environment; the CVSS score of 7.5 indicates high confidentiality impact with no direct integrity or availability loss. All deployments of Synology Drive Server on the affected branches are exposed, especially those with the web API reachable from the internet. No public proof-of-concept or confirmed in-the-wild exploitation has been reported so far, but EPSS rates the probability of exploitation in the next 30 days at 24.6% (98th percentile).

What to do: Upgrade Synology Drive Server to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, or 3.5.1-26102, matching the branch you currently run, or later. Until patched, keep the Drive web API off the public internet and restrict it to trusted networks via firewall or VPN; if internet exposure is suspected, rotate Drive administrator credentials and review access logs for anomalous API requests.

Affected
Synology Drive Serverall versions before 3.0.4-12699, before 3.2.1-23280, before 3.5.0-26085, and before 3.5.1-26102 (each fix applies to its respective branch)
Estimated exposure
large≈10,000–100,000 internet-exposed instances, of an installed base likely in the hundreds of thousands — Synology NAS units are deployed in the millions worldwide and Drive Server is one of its most common collaboration packages, while public internet scans report hundreds of thousands of exposed Synology DSM systems, only a subset of which…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.

Vendors
synology
Products
drive server
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.