Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. |
| Weaknesses | CWE-78 |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 14 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:synology:diskstation_manager:7.2:*:*:*:*:*:*:* |
cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:* |
Fri, 13 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:synology:photos:*:*:*:*:*:*:*:* |
cpe:2.3:a:synology:beephotos:*:*:*:*:*:beestation_os:*:* cpe:2.3:a:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:* cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:* |
Tue, 19 Nov 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology beephotos
Synology beestation Os Synology diskstation Manager Synology photos |
|
| CPEs | cpe:2.3:a:synology:beephotos:*:*:*:*:*:*:*:* cpe:2.3:a:synology:diskstation_manager:7.2:*:*:*:*:*:*:* cpe:2.3:a:synology:photos:*:*:*:*:*:*:*:* cpe:2.3:o:synology:beestation_os:1.0:*:*:*:*:*:*:* cpe:2.3:o:synology:beestation_os:1.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology beephotos
Synology beestation Os Synology diskstation Manager Synology photos |
Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology photo Station |
|
| CPEs | cpe:2.3:a:synology:photo_station:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Synology
Synology photo Station |
|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2025-09-16T06:02:16.158Z
Reserved: 2024-10-28T02:34:40.599Z
Link: CVE-2024-10443
Updated: 2024-11-15T17:42:07.286Z
Status : Modified
Published: 2024-11-15T11:15:09.750
Modified: 2025-09-16T06:16:04.327
Link: CVE-2024-10443
No data.
OpenCVE Enrichment
No data.