CVE-2024-10443
Synology BeeStation BST150-4T - Unauthenticated Command Injection
Record summary
CVE-2024-10443 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
BeePhotosBrowse Synology / BeePhotosDefault status: affected | CVE List | * to < 1.1.0-10053 | affected |
| * to < 1.0.2-10026 | affected | ||
Synology PhotosBrowse Synology / Synology PhotosDefault status: affected | CVE List | * to < 1.7.0-0795 | affected |
| * to < 1.6.2-0720 | affected | ||
photo_stationBrowse synology / photo_stationDefault status: unknown | CVE List | Before 1.6.2-0720 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSynology BeeStation BST150-4T - Unauthenticated Command InjectionCVSS 9.8
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Impact
Remote attackers can execute arbitrary code on the system, potentially leading to full system compromise.
Remediation
Upgrade Synology BeePhotos to version 1.0.2-10026 or 1.1.0-10053 or later, and Synology Photos to version 1.6.2-0720 or 1.7.0-0795 or later.
Source: ProjectDiscovery