Known vulnerabilities in Drive Server for DSM
Vendor:
Synology Inc.
Software:
Drive Server for DSM
Software CPE:
cpe:2.3:a:synology:drive_server_for_dsm:*:*:*:*:*:diskstation_manager_dsm:*:*
Website:
https://www.synology.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU107375 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-50631 |
CWE-89 | High | 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, 3.5.1-26102 | 11.04.2025 |
SB2025041106 |
||
| #VU107374 - Missing Authentication for Critical Function CVE-2024-50630 |
CWE-306 | High | 3.0.4-12699, 3.2.1-23280, 3.5.0-26085, 3.5.1-26102 | 11.04.2025 |
SB2025041106 |
||
| #VU99970 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CWE-89 | High | 3.5.1-26102 | 06.11.2024 |
SB2024110660 SB2024110661 SB2024110663 |