First published: Fri Nov 22 2024(Updated: )
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
<3.9.7 |
We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38644 is classified as a critical OS command injection vulnerability.
To fix CVE-2024-38644, upgrade to Notes Station 3 version 3.9.7 or later.
CVE-2024-38644 affects users of Notes Station 3 versions prior to 3.9.7.
If exploited, CVE-2024-38644 could allow remote authenticated attackers to execute arbitrary commands.
Yes, a patch for CVE-2024-38644 is included in Notes Station 3 version 3.9.7 and later.