CVE-2024-10443

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:o:synology:beestation_os:1.1:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:o:synology:beestation_os:1.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*

History

16 Sep 2025, 06:16

Type Values Removed Values Added
CWE CWE-78
Summary (en) Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. (en) Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

14 Jan 2025, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
cpe:2.3:a:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*

13 Dec 2024, 16:13

Type Values Removed Values Added
CPE cpe:2.3:a:synology:beephotos:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:photos:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:*
cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
cpe:2.3:a:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:*

19 Nov 2024, 19:15

Type Values Removed Values Added
CPE cpe:2.3:a:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
cpe:2.3:a:synology:beephotos:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:photos:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:beestation_os:1.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:beestation_os:1.0:*:*:*:*:*:*:*
First Time Synology photos
Synology beestation Os
Synology beephotos
Synology
Synology diskstation Manager
References () https://www.synology.com/en-global/security/advisory/Synology_SA_24_18 - () https://www.synology.com/en-global/security/advisory/Synology_SA_24_18 - Vendor Advisory
References () https://www.synology.com/en-global/security/advisory/Synology_SA_24_19 - () https://www.synology.com/en-global/security/advisory/Synology_SA_24_19 - Vendor Advisory

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando ('Inyección de comando') en Task Manager component in Synology BeePhotos anteriores a 1.0.2-10026 y 1.1.0-10053 y Synology Photos anteriores a 1.6.2-0720 y 1.7.0-0795 permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados.

15 Nov 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 11:15

Updated : 2025-09-16 06:16


NVD link : CVE-2024-10443

Mitre link : CVE-2024-10443

CVE.ORG link : CVE-2024-10443


JSON object : View

Products Affected

synology

  • beephotos
  • photos
  • diskstation_manager
  • beestation_os
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')