Qnap Notes Station 3 vulnerabilities

6 known vulnerabilities affecting qnap/notes_station_3.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-38643CRITICALCVSS 9.3≥ 3.9.0, < 3.9.72024-11-22
CVE-2024-38643 [CRITICAL] CWE-306 CVE-2024-38643: A missing authentication for critical function vulnerability has been reported to affect Notes Stati A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
nvd
CVE-2024-38645CRITICALCVSS 9.4≥ 3.9.0, < 3.9.72024-11-22
CVE-2024-38645 [CRITICAL] CWE-918 CVE-2024-38645: A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If e A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
nvd
CVE-2024-38646HIGHCVSS 8.4≥ 3.9.0, < 3.9.72024-11-22
CVE-2024-38646 [HIGH] CWE-732 CVE-2024-38646: An incorrect permission assignment for critical resource vulnerability has been reported to affect N An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and l
nvd
CVE-2024-38644HIGHCVSS 8.7≥ 3.9.0, < 3.9.72024-11-22
CVE-2024-38644 [HIGH] CWE-77 CVE-2024-38644: An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
nvd
CVE-2024-27122MEDIUMCVSS 5.4≥ 3.9.0, < 3.9.62024-09-06
CVE-2024-27122 [MEDIUM] CWE-79 CVE-2024-27122: A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
nvd
CVE-2024-27126MEDIUMCVSS 5.4≥ 3.9.0, < 3.9.62024-09-06
CVE-2024-27126 [MEDIUM] CWE-79 CVE-2024-27126: A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
nvd