7.5
CVE-2024-50630
- EPSS 0.69%
- Veröffentlicht 19.03.2025 05:50:05
- Zuletzt bearbeitet 16.01.2026 15:29:14
- Quelle security@synology.com
- CVE-Watchlists
- Unerledigt
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Synology ≫ Drive Server Version < 3.0.4-12699
Synology ≫ Drive Server Version < 3.2.1-23280
Synology ≫ Drive Server Version < 3.5.0-26085
Synology ≫ Drive Server Version < 3.5.1-26102
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.69% | 0.711 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@synology.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.