Record summary

CVE-2024-10443 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: affected

CVE List* to < 1.1.0-10053affected
* to < 1.0.2-10026affected

Default status: affected

CVE List* to < 1.7.0-0795affected
* to < 1.6.2-0720affected

Default status: unknown

CVE ListBefore 1.6.2-0720affected

Nuclei templates

1
ProjectDiscoveryCRITICALSynology BeeStation BST150-4T - Unauthenticated Command InjectionCVSS 9.8

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

Impact

Remote attackers can execute arbitrary code on the system, potentially leading to full system compromise.

Remediation

Upgrade Synology BeePhotos to version 1.0.2-10026 or 1.1.0-10053 or later, and Synology Photos to version 1.6.2-0720 or 1.7.0-0795 or later.

WeaknessesCWE-77
Authorsiamnoooob, pdresearch
Template tagsunauthsynologyrcewebsocketdiskstationvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:synology:photos:*:*:*:*:*:diskstation_manager:*:*
Shodan: html:"BeeStation"

Source: ProjectDiscovery

References

3