CVE-2024-38646

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*

History

20 Sep 2025, 03:29

Type Values Removed Values Added
References () https://www.qnap.com/en/security-advisory/qsa-24-36 - () https://www.qnap.com/en/security-advisory/qsa-24-36 - Vendor Advisory
CPE cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*
Summary
  • (es) Se ha informado de una vulnerabilidad de asignación de permisos incorrecta para un recurso crítico que afecta a Notes Station 3. Si se explota, la vulnerabilidad podría permitir que atacantes locales autenticados que hayan obtenido acceso de administrador lean o modifiquen el recurso. Ya hemos corregido la vulnerabilidad en la siguiente versión: Notes Station 3 3.9.7 y posteriores
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.0
First Time Qnap notes Station 3
Qnap

22 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 16:15

Updated : 2025-09-20 03:29


NVD link : CVE-2024-38646

Mitre link : CVE-2024-38646

CVE.ORG link : CVE-2024-38646


JSON object : View

Products Affected

qnap

  • notes_station_3
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource