CVE-2024-50630
largeUnauthenticated admin credential disclosure in Synology Drive Server webapi
Synology Drive Server versions prior to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, and 3.5.1-26102 contain a missing-authentication flaw (CWE-306) in the webapi component. Because the affected API function requires no credentials, a remote attacker can reach it over the network without user interaction and, via unspecified vectors, obtain administrator credentials. Successful exploitation gives the attacker administrative credentials for the Drive Server environment; the CVSS score of 7.5 indicates high confidentiality impact with no direct integrity or availability loss. All deployments of Synology Drive Server on the affected branches are exposed, especially those with the web API reachable from the internet. No public proof-of-concept or confirmed in-the-wild exploitation has been reported so far, but EPSS rates the probability of exploitation in the next 30 days at 24.6% (98th percentile).
What to do: Upgrade Synology Drive Server to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, or 3.5.1-26102, matching the branch you currently run, or later. Until patched, keep the Drive web API off the public internet and restrict it to trusted networks via firewall or VPN; if internet exposure is suspected, rotate Drive administrator credentials and review access logs for anomalous API requests.
| Synology Drive Server | all versions before 3.0.4-12699, before 3.2.1-23280, before 3.5.0-26085, and before 3.5.1-26102 (each fix applies to its respective branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
- Vendors
- synology
- Products
- drive server
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.