A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions.
We have already fixed the vulnerability in the following version:
Notes Station 3 3.9.7 and later
References
Link | Resource |
---|---|
https://www.qnap.com/en/security-advisory/qsa-24-36 | Vendor Advisory |
Configurations
History
20 Sep 2025, 03:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.qnap.com/en/security-advisory/qsa-24-36 - Vendor Advisory | |
First Time |
Qnap notes Station 3
Qnap |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:* |
Information
Published : 2024-11-22 16:15
Updated : 2025-09-20 03:32
NVD link : CVE-2024-38643
Mitre link : CVE-2024-38643
CVE.ORG link : CVE-2024-38643
JSON object : View
Products Affected
qnap
- notes_station_3
CWE
CWE-306
Missing Authentication for Critical Function