CVE-2024-38642Improper Certificate Validation in Systems INC Qumagie

Severity
1.0LOWNVD
EPSS
0.1%
top 76.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6

Description

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L

Affected Packages2 packages

CVEListV5qnap_systems_inc/qumagie2.3.x2.3.1
NVDqnap/qumagie2.3.0

🔴Vulnerability Details

2
GHSA
GHSA-78c9-5p24-9jcg: An improper certificate validation vulnerability has been reported to affect QuMagie2024-09-06
CVEList
QuMagie2024-09-06
CVE-2024-38642 — Improper Certificate Validation | cvebase