TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-38645

MEDIUM
6.5

Beschreibung

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE Details

CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht11/22/2024
Zuletzt geandert9/20/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

qnap:notes_station_3

Schwachen (CWE)

CWE-918

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.