CVE-2024-38645 Vulnerability Details

  /     /     /  

CVE-2024-38645 Metadata Quick Info

CVE Published: 22/11/2024 | CVE Updated: 22/11/2024 | CVE Year: 2024
Source: qnap | Vendor: QNAP Systems Inc. | Product: Notes Station 3
Status : PUBLISHED

CVE-2024-38645 Description

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-918
CWE Name: CWE-918
Source: QNAP Systems Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-664
CAPEC Description: CAPEC-664


Source: NVD (National Vulnerability Database).