CVE-2024-10443

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:o:synology:beestation_os:1.1:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:o:synology:beestation_os:1.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*

History

16 Sep 2025, 06:16

Type Values Removed Values Added
Summary (en) Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. (en) Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
CWE CWE-78

14 Jan 2025, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
cpe:2.3:a:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*

13 Dec 2024, 16:13

Type Values Removed Values Added
CPE cpe:2.3:a:synology:beephotos:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:photos:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:a:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*

Information

Published : 2024-11-15 11:15

Updated : 2025-09-16 06:16


NVD link : CVE-2024-10443

Mitre link : CVE-2024-10443

CVE.ORG link : CVE-2024-10443


JSON object : View

Products Affected

synology

  • diskstation_manager
  • beestation_os
  • photos
  • beephotos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')