← Vulnerability feed

Vulnerability record · CVE-2024-11399 · published 27 May 2026

CVE-2024-11399: Synology beedrive vulnerability

Synology · Beedrive

Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.

6.8 CVSS 3.1 Medium EPSS 0.11% · top 98.7% CWE-552 · CWE-552
6.8CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-11399 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-52945Synology beedrive uncontrolled search path element vulnerabilityUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to exe…EPSS 0.14%7.8CVE-2025-54160Synology beedrive path traversal vulnerabilityImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.…EPSS 0.20%7.8CVE-2025-54158Synology beedrive missing authentication for critical function vulnerabilityMissing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to exec…EPSS 0.18%7.5CVE-2025-54159Synology beedrive missing authorization vulnerabilityMissing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files…EPSS 0.41%5.6CVE-2025-8074Synology beedrive origin validation error vulnerabilityOrigin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files wit…EPSS 0.09%7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed7.5CVE-2020-17519Apache Flink JobManager REST interface arbitrary file readA change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to f…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2024-11399), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.