PT-2025-11662 · Synology · Synology Drive Server

Published

2024-11-05

·

Updated

2026-05-30

·

CVE-2024-50630

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Drive Server versions prior to 3.0.4-12699 Synology Drive Server versions prior to 3.2.1-23280 Synology Drive Server versions prior to 3.5.0-26085 Synology Drive Server versions prior to 3.5.1-26102
Description The issue is related to missing authentication for critical functions in the webapi component, allowing remote attackers to obtain administrator credentials via unspecified vectors.
Recommendations For versions prior to 3.0.4-12699, update to version 3.0.4-12699 or later. For versions prior to 3.2.1-23280, update to version 3.2.1-23280 or later. For versions prior to 3.5.0-26085, update to version 3.5.0-26085 or later. For versions prior to 3.5.1-26102, update to version 3.5.1-26102 or later.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-03831
CVE-2024-50630
ZDI-25-212

Affected Products

Synology Drive Server