CVE-2024-10443
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
9.8
CVSS
28.0%
EPSS (exploit prob.)
98th
EPSS percentile
2024-11-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| synology | photos | < 1.6.2-0720 |
| synology | diskstation_manager | 7.2 |
| synology | beephotos | < 1.1.0-10053 |
| synology | beestation_os | 1.1 |
| synology | beephotos | < 1.0.2-10026 |
| synology | beestation_os | 1.0 |
| synology | photos | < 1.7.0-0795 |
| synology | diskstation_manager | 7.2.2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-10443