CVE-2024-50631
largeUnauthenticated SQL Injection in Synology Drive Server Sync Daemon
CVE-2024-50631 is a SQL injection flaw (CWE-89) in the system syncing daemon of Synology Drive Server, allowing remote, unauthenticated attackers to inject SQL commands through unspecified vectors. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), exploitation requires no privileges or user interaction, and the impact is limited to write operations, so attackers can modify data in the underlying database but gain no read access or availability impact. Any organization or individual running an affected version of Synology Drive Server on a Synology NAS is exposed, particularly where the Drive service is reachable from the internet. As of now there is no known public proof-of-concept and the flaw is not in CISA's KEV catalog, but EPSS assigns a 26.2% probability of exploitation within 30 days (98th percentile), indicating a significant near-term risk.
What to do: Upgrade Synology Drive Server to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, or 3.5.1-26102 depending on your installed branch. Until patched, limit internet exposure of the Drive sync service (e.g., firewall it or require VPN access) and review for unexpected data modifications, since the flaw permits unauthorized writes.
| Synology Drive Server | all 3.0.x versions before 3.0.4-12699 |
| Synology Drive Server | all 3.2.x versions before 3.2.1-23280 |
| Synology Drive Server | 3.5.0 versions before 3.5.0-26085 and 3.5.1 versions before 3.5.1-26102 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors.
- Vendors
- synology
- Products
- drive server
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.