Known vulnerabilities in Notes Station 3
Vendor:
QNAP Systems, Inc.
Software:
Notes Station 3
Software CPE:
cpe:2.3:a:qnap_systems:notes_station_3:*:*:*:*:*:*:*:*
Website:
https://www.qnap.com
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU100885 - Incorrect Permission Assignment for Critical Resource CVE-2024-38646 |
CWE-732 | Low | 3.9.7 | 25.11.2024 |
SB2024112521 |
||
| #VU100884 - Server-Side Request Forgery (SSRF) CVE-2024-38645 |
CWE-918 | Medium | 3.9.7 | 25.11.2024 |
SB2024112521 |
||
| #VU100883 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-38644 |
CWE-78 | Medium | 3.9.7 | 25.11.2024 |
SB2024112521 |
||
| #VU100882 - Missing Authentication for Critical Function CVE-2024-38643 |
CWE-306 | High | 3.9.7 | 25.11.2024 |
SB2024112521 |
||
| #VU96955 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-27126 |
CWE-79 | Low | 3.9.6 | 09.09.2024 |
SB2024090949 |
||
| #VU96954 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-27122 |
CWE-79 | Low | 3.9.6 | 09.09.2024 |
SB2024090949 |