CVE-2024-38646

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*

History

20 Sep 2025, 03:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.0
First Time Qnap notes Station 3
Qnap
CPE cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*
References () https://www.qnap.com/en/security-advisory/qsa-24-36 - () https://www.qnap.com/en/security-advisory/qsa-24-36 - Vendor Advisory

Information

Published : 2024-11-22 16:15

Updated : 2025-09-20 03:29


NVD link : CVE-2024-38646

Mitre link : CVE-2024-38646

CVE.ORG link : CVE-2024-38646


JSON object : View

Products Affected

qnap

  • notes_station_3
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource