← Back

CVE-2024-10443

Published: Nov 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

Affected (4)

2 products
Photos
Beephotos
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.6.2-0720
Running on/withPlatform Versions
Synology
Diskstation Manager
Version 7.2
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0-10053
Running on/withPlatform Versions
Synology
Beestation Os
Version 1.1
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2-10026
Running on/withPlatform Versions
Synology
Beestation Os
Version 1.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.7.0-0795
Running on/withPlatform Versions
Synology
Diskstation Manager
Version 7.2.2

References (2)

Timeline

No history available yet.