7.5
CVE-2024-50630
- EPSS 0.09%
- Veröffentlicht 19.03.2025 05:50:05
- Zuletzt bearbeitet 19.03.2025 06:15:15
- Quelle security@synology.com
- CVE-Watchlists
- Unerledigt
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSynology
≫
Produkt
Synology Drive Server
Default Statusaffected
Version <
3.0.4-12699
Version
*
Status
affected
Version <
3.5.1-26102
Version
*
Status
affected
Version <
3.5.0-26085
Version
*
Status
affected
Version <
3.2.1-23280
Version
*
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.266 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@synology.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.