ZeroHour

CVE-2024-50631

large

Unauthenticated SQL Injection in Synology Drive Server Sync Daemon

CVSS 3.1
7.5 high
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2024-50631 is a SQL injection flaw (CWE-89) in the system syncing daemon of Synology Drive Server, allowing remote, unauthenticated attackers to inject SQL commands through unspecified vectors. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), exploitation requires no privileges or user interaction, and the impact is limited to write operations, so attackers can modify data in the underlying database but gain no read access or availability impact. Any organization or individual running an affected version of Synology Drive Server on a Synology NAS is exposed, particularly where the Drive service is reachable from the internet. As of now there is no known public proof-of-concept and the flaw is not in CISA's KEV catalog, but EPSS assigns a 26.2% probability of exploitation within 30 days (98th percentile), indicating a significant near-term risk.

What to do: Upgrade Synology Drive Server to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, or 3.5.1-26102 depending on your installed branch. Until patched, limit internet exposure of the Drive sync service (e.g., firewall it or require VPN access) and review for unexpected data modifications, since the flaw permits unauthorized writes.

Affected
Synology Drive Serverall 3.0.x versions before 3.0.4-12699
Synology Drive Serverall 3.2.x versions before 3.2.1-23280
Synology Drive Server3.5.0 versions before 3.5.0-26085 and 3.5.1 versions before 3.5.1-26102
Estimated exposure
large≈hundreds of thousands of NAS installations (100k–1M) running Synology Drive Server — Synology's NAS installed base is in the millions and Drive Server is one of its most widely deployed packages, so a substantial fraction — plausibly on the order of hundreds of thousands of active installs — is likely affected, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors.

Vendors
synology
Products
drive server
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.