PT-2025-11662 · Synology · Synology Drive Server

CVE-2024-50630

·

Published

2024-11-05

·

Updated

2026-05-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Drive Server versions prior to 3.0.4-12699 Synology Drive Server versions prior to 3.2.1-23280 Synology Drive Server versions prior to 3.5.0-26085 Synology Drive Server versions prior to 3.5.1-26102
Description The issue is related to missing authentication for critical functions in the webapi component, allowing remote attackers to obtain administrator credentials via unspecified vectors.
Recommendations For versions prior to 3.0.4-12699, update to version 3.0.4-12699 or later. For versions prior to 3.2.1-23280, update to version 3.2.1-23280 or later. For versions prior to 3.5.0-26085, update to version 3.5.0-26085 or later. For versions prior to 3.5.1-26102, update to version 3.5.1-26102 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03831
CVE-2024-50630
ZDI-25-212

Affected Products

Synology Drive Server