CVE-2024-38644: Notes Station 3
Published Nov 22, 2024
·Updated
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands.
We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Affected Software
2 affected components
Notes Station Notes Station 3<3.9.7
QNAP Notes Station 3>=3.9.0<3.9.7
Remediation
Information
We have already fixed the vulnerability in the following version:
Notes Station 3 3.9.7 and later
Event History
Nov 22, 2024
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 25, 2024
News Published
via BleepingComputer·10:13 PM
News Published
via BleepingComputer·10:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-38644?
CVE-2024-38644 is classified as a critical OS command injection vulnerability.
2
How do I fix CVE-2024-38644?
To fix CVE-2024-38644, upgrade to Notes Station 3 version 3.9.7 or later.
3
Who is affected by CVE-2024-38644?
CVE-2024-38644 affects users of Notes Station 3 versions prior to 3.9.7.
4
What could happen if CVE-2024-38644 is exploited?
If exploited, CVE-2024-38644 could allow remote authenticated attackers to execute arbitrary commands.
5
Is there a patch available for CVE-2024-38644?
Yes, a patch for CVE-2024-38644 is included in Notes Station 3 version 3.9.7 and later.