CVE-2024-50630: High severity Synology Drive Server vulnerability
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50630?
CVE-2024-50630 has been classified as a critical vulnerability due to the potential for remote attackers to gain administrator credentials.
How do I fix CVE-2024-50630?
To fix CVE-2024-50630, you should update Synology Drive Server to the latest version, specifically versions 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, or 3.5.1-26102.
What are the risks associated with CVE-2024-50630?
The risks associated with CVE-2024-50630 include unauthorized access to sensitive information and potential manipulation of files by malicious actors.
Which versions of Synology Drive Server are affected by CVE-2024-50630?
CVE-2024-50630 affects Synology Drive Server versions prior to 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, and 3.5.1-26102.
Can CVE-2024-50630 be exploited remotely?
Yes, CVE-2024-50630 can be exploited remotely, allowing attackers to potentially obtain administrator credentials without proper authentication.